DLL Hijacking in FileMaker Pro Installer for Windows
CVE-2026-86938

Currently unrated

Key Information:

Vendor

Claris

Vendor
CVE Published:
23 September 2026

What is CVE-2026-86938?

A local user can exploit a DLL hijacking vulnerability in the FileMaker Pro installer for Windows by placing a malicious DLL file into the installer directory. This flaw can potentially allow these users to execute arbitrary code with elevated administrator privileges, posing a significant security risk. This issue has been resolved in FileMaker Pro version 26.0.3, and it is critical for users to update to the latest version to mitigate this vulnerability.

Affected Version(s)

FileMaker Pro 0 < 26.0.3

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.