Executive brief
A security vulnerability in Claris FileMaker Cloud could allow an administrative user to bypass security controls and run unauthorized commands on the underlying server. FileMaker Cloud is a platform used for hosting custom business applications and databases. If exploited, an attacker with administrative access could gain full control over the server hosting the data, potentially leading to data theft or service disruption.
Technical details
A remote code execution vulnerability exists in Claris FileMaker Cloud due to improper validation of OS Script schedule types. An attacker with valid Admin Console privileges can bypass front-end restrictions to inject and execute arbitrary operating system commands on the underlying host. This is classified as a code injection (CWE-94) issue where the application fails to properly neutralize or restrict command execution to intended functions. The attack requires high privileges (Admin Console access) but can be executed over the network without user interaction. The issue is addressed in FileMaker Cloud version 2.22.0.5.
Affected products
- Claris FileMaker Cloud versions prior to 2.22.0.5
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory: Initial NVD publication
- 2026-05-12: patched: Fixed in version 2.22.0.5