We found a Claris FileMaker authorization bypass (CVE-2026-86934)
A client-controlled X-FMI-PE-ExtendedPrivilege header can bypass the disabled-feature check in the FileMaker Server XML Web Publishing Engine.
Restrict external access to /fmi/xml until patched and consult Claris security guidance for current fixed-version information.