7.2
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Description
A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to inject arbitrary operating system commands through unsanitized input in the External ODBC Data Source connection test feature. This issue is fixed in FileMaker Cloud 2.22.0.5.
Basic Information
ID
CVE-2026-43685
Source
apple
Published
May 12, 2026 at 22:24
Modified
May 13, 2026 at 00:17
Affected Product
Vendor
Claris
Product
FileMaker Cloud
Affected Versions
Claris FileMaker Cloud 0