Executive brief
Claris FileMaker Server, a platform used for hosting and managing custom business applications, contains a security flaw in its administrative console. An authorized administrator could potentially take full control of the underlying server by uploading a malicious file through the Large Language Model (LLM) setup tool. This could lead to a complete compromise of the server, including the theft or destruction of hosted business data.
Technical details
An arbitrary code execution vulnerability exists in Claris FileMaker Server due to insufficient validation during file uploads in the Open Source LLM setup feature. An authenticated attacker with administrative privileges can upload a malicious file (such as a Miniforge installer or similar executable) via the Admin Console to execute commands with the privileges of the server process. This bypasses intended restrictions on system-level modifications. The vulnerability is resolved in FileMaker Server version 26.0.1 by improving upload validation and handling within the Miniforge installer integration.
Affected products
- Claris FileMaker Server before 26.0.1
Timeline
- 2026-07-09: advisory: Initial disclosure by Apple/Claris
- 2026-07-09: patched: Fixed in version 26.0.1