CVE-2026-97360
Received
Received - Intake
Unauthenticated Arbitrary File Access in HFS2
Vulnerability report for CVE-2026-97360, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-24
Last updated on: 2026-09-24
Assigner: VulnCheck
Description
Description
HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the HFS service account has filesystem access outside the shared folder. Attackers can exploit the macro dispatcher's lack of authorization model combined with the path resolver's failure to confine absolute paths to manipulate the template engine and compromise the confidentiality, integrity, and availability of the host.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| rejetto | hfs | From 2.0.0 (inc) to 2.4.0 (inc) |
| rejetto | hfs | 2.4.0 |
| rejetto | hfs | 2.4.0_rc7 |
| rejetto | hfs | 2.4.0_rc8 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |