---
id: CVE-2026-86934
title: >-
  An authorization bypass vulnerability in the FileMaker Server Web Publishing
  Engine allowed requests containing an extended privilege header to bypass the
  disabled Custom Web Publishing with XML setting and access the XML Web
  Publishing …
summary: >-
  An authorization bypass vulnerability in the FileMaker Server Web Publishing
  Engine allowed requests containing an extended privilege header to bypass the
  disabled Custom Web Publishing with XML setting and access the XML Web
  Publishing …
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-639
vendor: Claris
product: FileMaker Server
affected:
  - filemaker_server < 26.0.3
published: '2026-09-23'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T15:17:49.783'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86934'
references:
  - url: 'https://support.claris.com/s/answerview?anum=000049217&language=en_US'
    label: product-security@apple.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-24T14:39:23.364539Z'
ingestedAt: '2026-09-23T17:28:14.860Z'
epss: 0.00148
epssPercentile: 0.03307
---

## Overview

An authorization bypass vulnerability in the FileMaker Server Web Publishing Engine allowed requests containing an extended privilege header to bypass the disabled Custom Web Publishing with XML setting and access the XML Web Publishing interface. This vulnerability is addressed in FileMaker Server version 26.0.3.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
