OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-86938

HIGH · CVSS 7.3 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

A DLL hijacking vulnerability in the FileMaker Pro installer for Windows enables local users to execute arbitrary code with elevated administrator privileges by inserting a malicious DLL into the installer directory. Organizations using affected versions of FileMaker Pro should prioritize patching to version 26.0.3 to mitigate the risk of unauthorized code execution and potential system compromise.

CVE
CVE-2026-86938
Severity
HIGH
CVSS
7.3
EPSS
0.10%
Windows

Original NVD Description

A DLL hijacking vulnerability in the FileMaker Pro installer for Windows allowed a local user to execute arbitrary code with elevated administrator privileges by placing a malicious DLL file in the installer directory. This vulnerability is addressed in FileMaker Pro version 26.0.3.

Related CVEs

Other vulnerabilities affecting the same vendor(s)