Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 23 Sep 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authorization Bypass via Privileged Header in FileMaker Server Web Publishing Engine | |
| Weaknesses | CWE-285 |
Wed, 23 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authorization bypass vulnerability in the FileMaker Server Web Publishing Engine allowed requests containing an extended privilege header to bypass the disabled Custom Web Publishing with XML setting and access the XML Web Publishing interface. This vulnerability is addressed in FileMaker Server version 26.0.3. | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: apple
Published:
Updated: 2026-09-23T17:20:20.178Z
Reserved: 2026-09-08T16:43:41.879Z
Link: CVE-2026-86934
No data.
Status : Awaiting Analysis
Published: 2026-09-23T18:17:09.847
Modified: 2026-09-23T18:22:36.150
Link: CVE-2026-86934
No data.
OpenCVE Enrichment
Updated: 2026-09-23T18:30:06Z
-
CWE-285
Improper Authorization