Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-61500: Rejetto HFS 3.0.0-3.2.0: Administrator Session Cookie Forgery Risk

CVE-2026-61500 CVE-2026-61500
Summary

Rejetto HFS, a web file manager, has a security flaw that allows an attacker to steal an administrator's session and take control of the server. This can happen if an attacker observes a few login attempts and uses that information to create a fake session. To fix this, update to a newer version of Rejetto HFS that has this vulnerability patched.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
rejetto hfs < 3.2.1
Original title
Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients duri...
Original description
Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login. A remote attacker can collect a small number of login responses, reconstruct the generator's state, recover the signing key, and forge a valid administrator session cookie, leading to full administrative access and remote code execution via the server_code configuration feature.
nvd CVSS3.1 9.8
nvd CVSS4.0 9.3
Vulnerability type
CWE-338
Published: 13 Jul 2026 · Updated: 20 Jul 2026 · First seen: 13 Jul 2026