Authorization Bypass in FileMaker Server Web Publishing Engine
CVE-2026-86934
Currently unrated
What is CVE-2026-86934?
An authorization bypass vulnerability exists in the FileMaker Server Web Publishing Engine, which allows attackers to bypass the disabled Custom Web Publishing with XML setting. This flaw enables unauthorized access to the XML Web Publishing interface by sending requests with an extended privilege header. The issue has been addressed in FileMaker Server version 26.0.3.
Affected Version(s)
FileMaker Server 0 < 26.0.3
