CVE-2025-46296
An authorization bypass vulnerability in FileMaker Server Admin Console allowed administrator roles with minimal privileges to access administrative features such as viewing license details and downloading application logs. This vulnerability has been fully addressed in FileMaker Server 22.0.4.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46296?
CVE-2025-46296 is considered a high severity vulnerability due to its potential for unauthorized access to sensitive administrative features.
How do I fix CVE-2025-46296?
To fix CVE-2025-46296, upgrade to FileMaker Server version 22.0.4 or later.
What are the consequences of CVE-2025-46296?
The consequences of CVE-2025-46296 include possible exposure of confidential license details and sensitive application logs to unauthorized users.
Who is affected by CVE-2025-46296?
CVE-2025-46296 affects users of Claris FileMaker Server versions prior to 22.0.4.
What does the CVE-2025-46296 vulnerability allow?
CVE-2025-46296 allows users with limited administrator roles to bypass authorization and access restricted administrative functionalities.