Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-97359: HFS2 allows attackers to run code via crafted upload filename

CVE-2026-97359 · published 16 days ago
Summary

Versions of HFS2 up to 2.4.0 let anyone upload a file with a specially crafted name that can cause the server to execute arbitrary commands. This can happen without any login, giving attackers control over the host system. Update to a newer version or apply the vendor's patch, and consider limiting or validating file upload names to protect your server.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
rejetto hfs2 <= 2.4.0
Original advisory text
HFS2 2.4.0 RCE via Multipart Upload Filename Template Injection
HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated attackers to achieve remote code execution by embedding malicious template syntax in a filename. Attackers can craft a filename containing a closing template quoting sequence followed by an exec macro, which bypasses the authorization check in the dispatcher to execute arbitrary commands on the underlying host system.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
10.0 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-1336Improper Neutralization of Special Elements Used in a Template Engine
Timeline
Published24 Sep 2026
Updated7 Oct 2026
First seen24 Sep 2026
Sources
CVE-2026-97359 · MITRE
Track software like this
Free during beta