CVE-2026-43752: Malicious File Upload
Published Jul 9, 2026
·Updated
An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicious file through the Open Source LLM setup feature in the Admin Console. This vulnerability has been addressed in FileMaker Server 26.0.1.
Affected Software
2 affected components
FileMaker Filemaker Server<26.0.1
Claris FileMaker Server<26.0.1
Event History
Jul 9, 2026
CVE Published
via MITRE·05:19 PM
Data Sourced
via MITRE·05:19 PM
DescriptionWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-43752?
The severity of CVE-2026-43752 is rated as medium with a CVSS score of 4.9.
2
How do I fix CVE-2026-43752?
To fix CVE-2026-43752, upgrade to FileMaker Server version 26.0.1 or later.
3
What type of vulnerability is CVE-2026-43752?
CVE-2026-43752 is classified as a Malicious File Upload vulnerability.
4
Who is affected by CVE-2026-43752?
CVE-2026-43752 affects authenticated administrators of FileMaker Server who can upload files via the Admin Console.
5
What impact does CVE-2026-43752 have on the system?
CVE-2026-43752 can potentially allow arbitrary code execution on the host system.