{"id":"CVE-2026-86930","published":"2026-09-23T18:17:09.720","lastModified":"2026-09-24T15:17:49.620","description":"An out-of-bounds read vulnerability in FileMaker Server for Linux allowed an attacker uploading a specially crafted image file to a container field to disclose process memory during thumbnail generation in FileMaker WebDirect. This vulnerability is addressed in FileMaker Server version 26.0.3.","cvssScore":9.1,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","cwes":["CWE-125"],"vendors":[],"products":[],"references":[{"url":"https://support.claris.com/s/answerview?anum=000049218&language=en_US","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"This vulnerability allows an attacker to read process memory during thumbnail generation in FileMaker WebDirect by uploading a specially crafted image file to a container field. This can lead to sensitive information disclosure.","exploitability":"Exploitation requires uploading a crafted image file to a container field, which is relatively easy given the attacker's control over the file upload process.","blast_radius":"If exploited, the attacker could gain access to sensitive information stored in the process memory, potentially leading to data breaches.","remediation":"Upgrade to FileMaker Server version 26.0.3 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["memory-disclosure","file-upload","web-direct"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T08:52:09.992Z"}}