CVE-2026-61501 Details
Description
Rejetto HFS 3.0.0 through 3.2.0 renders log entries in the administration panel as HTML without sanitization. A remote unauthenticated attacker can submit a failed login with a crafted username that is written to the error log and executes JavaScript in an administrator's browser when the logs are viewed, allowing the attacker to create accounts or execute code on the server with the administrator's privileges.
A stored cross-site scripting vulnerability has been identified in Rejetto HFS versions 3.0.0 prior to 3.2.1. The issue arises because log entries in the administration panel are rendered as HTML without proper sanitization. This flaw allows remote unauthenticated attackers to submit failed login attempts with crafted usernames. The malicious JavaScript embedded in these usernames is executed in the administrator's browser when the error logs are viewed. As a result, attackers could potentially create accounts or execute code on the server with the administrator's privileges.
Users are advised to update to Rejetto HFS version 3.2.1 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 13, 2026CISA-ADP
Assessed Jul 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/rejetto/hfs/releases/tag/v3.2.1 | [email protected] | Release NotesVendor |
| https://www.vulncheck.com/advisories/rejetto-hfs-stored-xss-in-admin-log-viewer | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Rejetto HFS | >= 3.0.0, <= 3.2.0 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jul 14, 2026 | CVE Modified | CISA-ADP |
| Jul 13, 2026 | New CVE Received | [email protected] |
Volerion