Security Advisory: OttoFMS 4.16.0 Update Available (Ottomatic Servers Already Patched)

Hi everyone,

We want to share an important security update regarding OttoFMS.

What happened:

During internal security testing, we identified a vulnerability affecting OttoFMS versions prior to 4.16.0 that allowed unauthenticated data overwrite.

We have no evidence that this vulnerability was exploited in the wild, however we treated this as a priority issue and moved quickly to address it.

What we did:

The issue has been fully resolved in OttoFMS version 4.16.0, which is now available.

If you manage OttoFMS yourself:

If you are running OttoFMS outside of the Ottomatic managed platform, we strongly recommend upgrading to version 4.16.0 as soon as possible. If you do not upgrade, you are at risk of losing your data.

Upgrade instructions are available here: OttoFMS - Updating OttoFMS

We recommend treating this as a priority update.

If your FileMaker Server is hosted on Ottomatic:

No action is required.

All Ottomatic-hosted FileMaker Servers have already been automatically updated to OttoFMS 4.16.0 as part of our managed security maintenance process. Your systems are already protected.

Our commitment:

Security transparency is important to us. When issues are identified, our goal is to remediate quickly, communicate clearly, and ensure customers have the information they need to stay protected.

If you have any questions, please reach out via the forum.

Thank you for being part of the community,

The Ottomatic by Proof+Geist Team

2 Likes

I upgraded to 4.16.1 and now I can no longer connect to claude desktop for my MCP server. everything was working fine prior to the update. I have rebooted teh Server and Claude several times.

Hey Ashley,

There is an issue that’s been reported with the OData MCPs in 4.16. I’m planning on releasing a fix on Monday for the issue. Sorry for the inconvenience.

-Kyle

I saw an uninstaller for the pervious version but I no longer see one. how do I uninstall 4.16.1?

There should be an uninstaller present in the OttoFMS application directory. If you use the terminal command to do the upgrade or downgrade it will run the uninstall for you: OttoFMS - Updating OttoFMS

-Kyle