External risk intelligence

FileMaker Server Web Publishing Authorization Bypass Affects XML Interface.

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-86934

FileMaker Server is commonly deployed to host databases and web services. The vulnerability involves the Web Publishing Engine, an interface frequently exposed to the network or internet to allow external users or systems to interact with the hosted database via XML or web protocols.

Claris Filemaker Server

before 26.0.3

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details a critical authorization bypass vulnerability in the FileMaker Server Web Publishing Engine. It allows unauthenticated access to sensitive data through the XML Web Publishing interface, bypassing existing security controls. The primary concern is confirming the relevance and exposure of this technology within your environment.

  • Access bypass in web publishing engine.
  • Critical flaw: bypasses security for data access.
  • Confirm relevance and exposure of FileMaker Server.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending a specially crafted request to the FileMaker Server's Web Publishing Engine. This request, which includes an extended privilege header, can bypass a security setting that disables custom web publishing with XML. Successfully exploiting this allows the attacker to access the XML Web Publishing interface, potentially leading to unauthorized data access or manipulation.

  • No authentication required for access.
  • Triggered by requests with extended privilege headers.
  • Risk of unauthorized access to XML interface.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow unauthorized access to the XML Web Publishing interface of FileMaker Server, potentially exposing sensitive data. This could occur when the Custom Web Publishing with XML setting is disabled but the server is accessible over the network.

  • Sensitive data within FileMaker Server databases.
  • Unauthorized access via specific HTTP requests.
  • Potential for data exposure or modification.

Operational Fix

Recommended remediation, mitigation, and detection steps

This FileMaker Server authorization bypass affects the Web Publishing Engine, likely managed by application owners or platform teams responsible for database services. The first practical step is to locate all FileMaker Server instances, assess their external reachability and business criticality, identify the accountable owner, and then prioritize remediation based on risk.

  • Identify FileMaker Server instances.
  • Verify external exposure and business criticality.
  • Plan remediation with vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Claris FileMaker Server?

FileMaker Server is a platform used to host custom applications and databases. It includes a Web Publishing Engine that allows these databases to interact with web services and external systems, effectively serving as the bridge between your stored data and network-based requests.

How does CVE-2026-86934 bypass security?

This vulnerability is an authorization bypass, specifically categorized as CWE-639 (Authorization Bypass Through User-Controlled Key). It works by manipulating the server's permission checks; by including a specific header in a network request, an attacker can trick the system into ignoring the configuration setting that is supposed to disable the XML-based publishing interface.

When does this vulnerability trigger?

The flaw is triggered when a server receives an HTTP request containing a specific extended privilege header. Importantly, if the XML Web Publishing interface is already properly disabled and the request does not include this header, the vulnerability does not manifest. The core issue is the server incorrectly overriding the disabled setting upon receiving the crafted header.

Is my FileMaker Server at risk?

According to Halo Surface Signal, risk is higher if your server is accessible over the network or the internet. Because the Web Publishing Engine is designed to facilitate database interactions, any instance that faces the network may be reachable by unauthorized parties attempting to exploit this interface, regardless of your internal administrative security settings.

What should I do first to secure my server?

Begin by creating an inventory of all FileMaker Server instances running in your environment. Once identified, verify their network accessibility and determine which ones are intended to be internet-facing. After assessing the criticality of the hosted data, coordinate with your infrastructure team to update to version 26.0.3 or higher to resolve the authorization logic error.

References