Authorization Bypass in FileMaker Server Web Publishing Engine
CVE-2026-86934

Currently unrated

Key Information:

Vendor

Claris

Vendor
CVE Published:
23 September 2026

What is CVE-2026-86934?

An authorization bypass vulnerability exists in the FileMaker Server Web Publishing Engine, which allows attackers to bypass the disabled Custom Web Publishing with XML setting. This flaw enables unauthorized access to the XML Web Publishing interface by sending requests with an extended privilege header. The issue has been addressed in FileMaker Server version 26.0.3.

Affected Version(s)

FileMaker Server 0 < 26.0.3

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.