PT-2026-40461 · Clarisa · Filemaker Cloud

Published

2026-05-12

·

Updated

2026-05-13

·

CVE-2026-43685

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Claris FileMaker Cloud versions prior to 2.22.0.5
Description A Remote Code Execution issue allows a user with Admin Console privileges to inject arbitrary operating system commands. This occurs due to unsanitized input within the External ODBC Data Source connection test feature.
Recommendations Update to version 2.22.0.5.

Fix

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-43685

Affected Products

Filemaker Cloud