CVE-2026-97360 Details
Description
HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the HFS service account has filesystem access outside the shared folder. Attackers can exploit the macro dispatcher's lack of authorization model combined with the path resolver's failure to confine absolute paths to manipulate the template engine and compromise the confidentiality, integrity, and availability of the host.
A vulnerability in Rejetto HTTP File Server (HFS) version 2.4.0 and earlier allows unauthenticated attackers to perform arbitrary file operations outside the shared folder. This is achieved through the template engine's macro dispatching, which lacks authorization checks, combined with a path resolver that fails to restrict absolute paths. As a result, attackers can read, write, append, and delete files anywhere the HFS service account has access, compromising the host's confidentiality, integrity, and availability.
Users are advised to update to HFS 3.x, the only maintained branch, and to run the application with a minimal privilege account that has restricted file system access. Additionally, avoid exposing HFS 2.x to untrusted networks.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 24, 2026CISA-ADP
Assessed Sep 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/wgetnz/hfs2/blob/master/advisories/hfs2-template-macro-missing-authorization/README.md | [email protected] | AdvisoryExploitRemedyTechnical Analysis |
| https://www.vulncheck.com/advisories/hfs2-unauthenticated-arbitrary-file-read-write-via-template-engine | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Rejetto HTTP File Server | >= 2.0.0, <= 2.4.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 24, 2026 | CVE Modified | CISA-ADP |
| Sep 24, 2026 | New CVE Received | [email protected] |
Volerion