{"id":"CVE-2026-86926","title":"A heap buffer overflow vulnerability in the FileMaker Server database engine block parsing routine allowed a maliciously crafted .fmp12 database file to cause memory corruption, potentially leading to arbitrary code execution","summary":"A heap buffer overflow vulnerability in the FileMaker Server database engine block parsing routine allowed a maliciously crafted .fmp12 database file to cause memory corruption, potentially leading to arbitrary code execution. This vulne…","severity":"none","vendor":"Claris","product":"FileMaker Server","affected":["filemaker_server < 26.0.3"],"published":"2026-09-23","updated":"2026-09-23","sourceUpdated":"2026-09-23T18:22:36.150","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-86926","references":[{"url":"https://support.claris.com/s/answerview?anum=000049219&language=en_US","label":"product-security@apple.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-23T17:28:14.861Z","slug":"CVE-2026-86926","body":"## Overview\n\nA heap buffer overflow vulnerability in the FileMaker Server database engine block parsing routine allowed a maliciously crafted .fmp12 database file to cause memory corruption, potentially leading to arbitrary code execution. This vulnerability is addressed in FileMaker Server version 26.0.3.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}