OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-86930

CRITICAL · CVSS 9.1 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

An out-of-bounds read vulnerability in FileMaker Server for Linux can be exploited by an attacker who uploads a specially crafted image file, potentially disclosing sensitive process memory during thumbnail generation in FileMaker WebDirect. Organizations using affected versions of FileMaker Server should prioritize patching to version 26.0.3 to mitigate the risk of data exposure. This vulnerability is particularly relevant for environments that utilize FileMaker WebDirect for web-based database access.

CVE
CVE-2026-86930
Severity
CRITICAL
CVSS
9.1
EPSS
0.29%
Linux

Original NVD Description

An out-of-bounds read vulnerability in FileMaker Server for Linux allowed an attacker uploading a specially crafted image file to a container field to disclose process memory during thumbnail generation in FileMaker WebDirect. This vulnerability is addressed in FileMaker Server version 26.0.3.

Related CVEs

Other vulnerabilities affecting the same vendor(s)