OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-86934

CRITICAL · CVSS 9.1 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

An authorization bypass vulnerability in the FileMaker Server Web Publishing Engine allows unauthorized access to the XML Web Publishing interface by exploiting requests with an extended privilege header, even when Custom Web Publishing with XML is disabled. Organizations using affected versions of FileMaker Server should prioritize patching to version 26.0.3 to mitigate potential unauthorized data access risks. This is particularly critical for environments handling sensitive data or relying on the security of their web publishing configurations.

CVE
CVE-2026-86934
Severity
CRITICAL
CVSS
9.1
EPSS
0.32%

Original NVD Description

An authorization bypass vulnerability in the FileMaker Server Web Publishing Engine allowed requests containing an extended privilege header to bypass the disabled Custom Web Publishing with XML setting and access the XML Web Publishing interface. This vulnerability is addressed in FileMaker Server version 26.0.3.

Related CVEs

Other vulnerabilities affecting the same vendor(s)