Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.3

CVE-2026-61501: Rejetto HFS allows attackers to execute code in admin browser

CVE-2026-61501 CVE-2026-61501
Summary

Rejetto HFS 3.0.0 through 3.2.0 is affected. An attacker can trick an administrator into viewing a malicious log entry, potentially allowing them to create new accounts or execute code on the server with admin privileges. Update to a fixed version to prevent this.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
rejetto hfs < 3.2.1
Original title
Rejetto HFS 3.0.0 through 3.2.0 renders log entries in the administration panel as HTML without sanitization. A remote unauthenticated attacker can submit a failed login with a crafted username tha...
Original description
Rejetto HFS 3.0.0 through 3.2.0 renders log entries in the administration panel as HTML without sanitization. A remote unauthenticated attacker can submit a failed login with a crafted username that is written to the error log and executes JavaScript in an administrator's browser when the logs are viewed, allowing the attacker to create accounts or execute code on the server with the administrator's privileges.
nvd CVSS3.1 6.1
nvd CVSS4.0 5.3
Vulnerability type
CWE-79 Cross-site Scripting (XSS)
Published: 13 Jul 2026 · Updated: 18 Jul 2026 · First seen: 13 Jul 2026