CVE-2026-86930
9.1 CRITICALPublished 2026-09-23 · Updated 2026-09-24
AI risk analysis
- Summary
- This vulnerability allows an attacker to read process memory during thumbnail generation in FileMaker WebDirect by uploading a specially crafted image file to a container field. This can lead to sensitive information disclosure.
- Exploitability
- Exploitation requires uploading a crafted image file to a container field, which is relatively easy given the attacker's control over the file upload process.
- Blast radius
- If exploited, the attacker could gain access to sensitive information stored in the process memory, potentially leading to data breaches.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to FileMaker Server version 26.0.3 or later.
memory-disclosurefile-uploadweb-direct
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
An out-of-bounds read vulnerability in FileMaker Server for Linux allowed an attacker uploading a specially crafted image file to a container field to disclose process memory during thumbnail generation in FileMaker WebDirect. This vulnerability is addressed in FileMaker Server version 26.0.3.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Weaknesses
CWE-125
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-13249
- CRITICALCVE-2026-93616
- HIGHCVE-2026-100387PoC
- MEDIUMCVE-2026-100505PoC
- MEDIUMCVE-2026-101204
- MEDIUMCVE-2026-101205
- MEDIUMCVE-2026-102318
- HIGHCVE-2026-102360PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.