External risk intelligence

FileMaker Server Linux Out-of-Bounds Read Discloses Process Memory in WebDirect.

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-86930

FileMaker WebDirect is designed to expose FileMaker databases as web applications to users over the internet or internal networks. Because the vulnerability is triggered via this public-facing web interface, it is commonly deployed in an internet-accessible configuration.

Out-of-bounds Read

Claris Filemaker Server

before 26.0.3

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability was identified in FileMaker Server for Linux that could allow an attacker to access sensitive process memory by uploading a specially crafted image file. This issue impacts FileMaker WebDirect, a component that makes FileMaker databases accessible via web browsers. The concern is the potential for unauthorized disclosure of internal system information.

  • Memory exposure via specially crafted image files.
  • Affects web-accessible database interfaces.
  • Confirm relevance and exposure of web-facing services.

Attack Path

How an attacker could exploit the issue

An attacker could upload a malicious image file to a FileMaker Server for Linux that is exposed to the network. This specially crafted file would then be processed by FileMaker WebDirect during thumbnail generation, leading to the disclosure of sensitive process memory.

  • No authentication or user interaction required.
  • Upload a malicious image file.
  • Process memory disclosure.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, an out-of-bounds read vulnerability in FileMaker Server for Linux could allow an attacker to disclose process memory during thumbnail generation in FileMaker WebDirect by uploading a specially crafted image file to a container field.

  • Process memory.
  • Specially crafted image upload.
  • Disclosure of sensitive information.

Operational Fix

Recommended remediation, mitigation, and detection steps

Identifying the specific teams responsible for addressing this FileMaker Server vulnerability involves understanding how the application is deployed and managed within your organization. Typically, the application owners who manage the FileMaker databases and their associated WebDirect interfaces, along with the infrastructure or platform teams supporting the Linux environment where FileMaker Server runs, will need to collaborate. The first practical step is to ascertain the scope of deployment: determine all instances of FileMaker Server, confirm their external reachability and business criticality, and then pinpoint the accountable owner for each instance before planning remediation based on the assessed risk.

  • Application owners and platform teams own remediation.
  • Verify FileMaker Server reachability and criticality.
  • Plan and coordinate vendor-supported updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is FileMaker Server for Linux?

FileMaker Server is a backend application platform used to host databases. The Linux version allows organizations to run these databases on Linux environments, supporting features like WebDirect, which lets users interact with those databases directly through a web browser without needing the full client software installed.

What does an out-of-bounds read mean for CVE-2026-86930?

This vulnerability is classified as CWE-125. It means the software reads data past the end of an intended memory buffer. In this case, the process improperly accesses its own internal memory while trying to generate a thumbnail for an image, potentially leaking sensitive information contained in that memory space to an attacker.

How is this vulnerability triggered?

An attacker triggers this by uploading a specifically formatted image file to a container field within the system. The vulnerability is tied to the thumbnail generation process in WebDirect. It does not occur when interacting with standard text fields or database records that do not involve image processing tasks.

Is my server at risk if it uses WebDirect?

Halo Surface Signal indicates that because this flaw is reachable via the WebDirect interface, instances deployed in an internet-accessible configuration face higher risk. If your WebDirect interface is exposed to the public internet, it provides a direct path for remote exploitation without requiring authentication.

How do I secure my environment against this vulnerability?

First, identify all instances of FileMaker Server running on Linux within your infrastructure to determine which ones use WebDirect. Once you have an inventory, coordinate with your database and platform teams to apply the vendor-provided update to version 26.0.3 or later, which contains the fix for this memory handling issue.

References