Skip to content
appleCVE-2026-86934

An authorization bypass vulnerability in the FileMaker Server Web Publishing Engine allowed requests containing an extended privilege header to bypass the disabled Custom Web Publishing with XML...

Critical9.1CVE-2026-86934 · Published Sep 23, 2026 · updated Sep 24, 2026

Source advisory

Affected versions

PackageAffectedFixed in
FileMaker Server
Vendor
< 26.0.326.0.3
Details and references

An authorization bypass vulnerability in the FileMaker Server Web Publishing Engine allowed requests containing an extended privilege header to bypass the disabled Custom Web Publishing with XML setting and access the XML Web Publishing interface. This vulnerability is addressed in FileMaker Server version 26.0.3.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity from
no source yet
Weakness
CWE-639

More apple advisories

All
DateAdvisory
Sep 23A heap buffer overflow vulnerability in the FileMaker Server database engine block parsing routine allowed a maliciously crafted .
CVE-2026-86926High7.8fixed in FileMaker Server 26.0.3
Sep 23An out-of-bounds read vulnerability in FileMaker Server for Linux allowed an attacker uploading a specially crafted image file to a container field to disclose process memory during thumbnail...
CVE-2026-86930Critical9.1fixed in FileMaker Server 26.0.3
Sep 23A DLL hijacking vulnerability in the FileMaker Pro installer for Windows allowed a local user to execute arbitrary code with elevated administrator privileges by placing a malicious DLL file in the...
CVE-2026-86938High7.3fixed in FileMaker Pro 26.0.3
Sep 14A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS Sonoma 14.8.8.
CVE-2026-86902Medium5.5fixed in macOS 14.8.8, macOS 27
Sep 14An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27.
CVE-2026-86903Medium5.5fixed in iOS and iPadOS 27, macOS 27, tvOS 27
Sep 14A privacy issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, watchOS 27.
CVE-2026-86904High7.5fixed in iOS and iPadOS 26.7, iOS and iPadOS 27, watchOS 27

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.