AppleCVE-2026-43752
Apple FileMaker Server: code execution
Medium4.9CVE-2026-43752 · Published Jul 9, 2026 · updated Jul 10, 2026
An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicious file through the Open Source LLM setup feature in the Admin Console. This vulnerability has been addressed in FileMaker Server 26.0.1.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| FileMaker Server Product | < 26.0.1 | 26.0.1 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- Severity from
- CISA (its enrichment of the CVE record)
- Weakness
- CWE-434
More Apple advisories
All Apple| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 17 | Unauthenticated out-of-bounds stack write via oversized ECDSA signature in swift-nio-ssh | Critical | 0.14.1 |
| Jul 16 | Double-free when parsing RSA public key fails | Critical | 4.5.1 |
| Jul 15 | Accessing bytes of non-string SAN can lead to out-of-bounds memory read | Critical | 2.37.2 |
| Jul 9 | DoS via WebSocket frame with oversize 64-bit payload length field (Int trap in WebSocketFrameDecoder) | High7.5 | 2.101.0 |
| Jul 8 | Packages can be read/written outside the configured cache directory | Medium | 0.32.0 |
| Jul 8 | Remote packages can read files past a local package dependency root | Low | 0.32.0 |