Description
An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicious file through the Open Source LLM setup feature in the Admin Console. This vulnerability has been addressed in FileMaker Server 26.0.1.
CVSS 4.9EPSS 0.49%Risk 0.51
View source- Published
- 2026-07-09 18:16:52
- Affected versions
- <26.0.1
- Type
- Critical software
- VectorCVSS:3.1
- Attack vectorNetworkAttack complexityLowPrivileges requiredHighUser interactionNoneScopeUnchangedConfidentialityHighIntegrityNoneAvailabilityNone