CVE-2026-86926: Buffer Overflow
A heap buffer overflow vulnerability in the FileMaker Server database engine block parsing routine allowed a maliciously crafted .fmp12 database file to cause memory corruption, potentially leading to arbitrary code execution. This vulnerability is addressed in FileMaker Server version 26.0.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FileMaker Serverto a version that resolves this vulnerability.Fixed in 26.0.3
Event History
Frequently Asked Questions
What does an attacker need to exploit this vulnerability?
An attacker needs to provide a maliciously crafted .fmp12 database file that is processed by the FileMaker Server database engine.
Which deployments should be prioritized for remediation?
Prioritize FileMaker Server instances that process .fmp12 database files from untrusted or insufficiently validated sources, since parsing a crafted file can cause memory corruption and may allow arbitrary code execution.
What version addresses the issue?
The vulnerability is addressed in FileMaker Server version 26.0.3.