Executive brief
Claris FileMaker Cloud, a platform used for hosting and managing custom business applications, contained a security flaw in its administrative interface. An authorized administrator could have executed unauthorized commands on the underlying server by providing malicious input during a database connection test. This could lead to a complete takeover of the server, potentially exposing sensitive business data or disrupting operations.
Technical details
A command injection vulnerability (CWE-78) exists in the Claris FileMaker Cloud Admin Console. The flaw is located in the External ODBC Data Source connection test feature, which failed to properly sanitize user-provided input before passing it to a system shell. An attacker with high-level administrative privileges could exploit this by submitting specially crafted strings to execute arbitrary OS commands with the privileges of the web service. This issue is resolved in FileMaker Cloud version 2.22.0.5.
Affected products
- Claris FileMaker Cloud versions prior to 2.22.0.5
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory
- 2026-05-12: patched: Fixed in version 2.22.0.5