Home

Description

A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to bypass a front-end restriction on OS Script schedule types and execute arbitrary operating system commands on the underlying host. This issue is fixed in FileMaker Cloud 2.22.0.5.

PUBLISHED Reserved 2026-05-01 | Published 2026-05-12 | Updated 2026-05-13 | Assigner apple

Problem types

A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to bypass a front-end restriction on OS Script schedule types and execute arbitrary operating system commands on the underlying host.

Product status

Any version before 2.22.0.5
affected

References

support.claris.com/...swerview?anum=000049153&language=en_US

cve.org (CVE-2026-43680)

nvd.nist.gov (CVE-2026-43680)

Download JSON