CVE-2026-86934 debrief based on the supplied source corpus. The vulnerability is an authorization bypass in the FileMaker Server Web Publishing Engine, allowing requests with an extended privilege header to bypass the disabled Custom Web Publishing with XML setting and access the XML Web Publishing interface. This issue is addressed in FileMaker Server version 26.0.3. Defenders should assess exposure and [truncated]
A critical vulnerability, CVE-2026-86930, exists in FileMaker Server for Linux. This vulnerability allows attackers to disclose process memory by uploading a specially crafted image file to a container field, which is then used to generate thumbnails in FileMaker WebDirect. The issue is addressed in FileMaker Server version 26.0.3. System administrators and security teams should assess exposure and apply [truncated]
A heap buffer overflow vulnerability in FileMaker Server's database engine block parsing routine could allow memory corruption from a malicious .fmp12 database file, potentially leading to arbitrary code execution. This issue is addressed in FileMaker Server version 26.0.3. The vulnerability exists due to improper handling of .fmp12 database files, which can be crafted to cause memory corruption. Defender [truncated]
An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicious file through the Open Source LLM setup feature in the Admin Console. This vulnerability has been addressed in FileMaker Server 26.0.1. The vulnerability has a CVSS score of 4.9 and is considered medium-severity. The vulnerability requires administrative privileges to exploit.