Home

Description

A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to inject arbitrary operating system commands through unsanitized input in the External ODBC Data Source connection test feature. This issue is fixed in FileMaker Cloud 2.22.0.5.

PUBLISHED Reserved 2026-05-01 | Published 2026-05-12 | Updated 2026-05-13 | Assigner apple

Problem types

A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to inject arbitrary operating system commands through unsanitized input in the External ODBC Data Source connection test feature.

Product status

Any version before 2.22.0.5
affected

References

support.claris.com/...swerview?anum=000049154&language=en_US

cve.org (CVE-2026-43685)

nvd.nist.gov (CVE-2026-43685)

Download JSON