Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-97360: HFS2 allows outsiders to read, change, delete any file
CVE-2026-97360 · published 16 days ago
Summary
Versions of HFS2 up to 2.4.0 let anyone on the network read, modify, add to, or delete files that the HFS service can reach, even outside the shared folder. This can expose private data, corrupt information, or disrupt operations. Upgrade to a newer release or apply the vendor’s patch and limit the service account’s file permissions to reduce the risk.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| rejetto | hfs2 | <= 2.4.0 |
Original advisory text
HFS2 2.4.0 Unauthenticated Arbitrary File Read/Write via Template Engine
HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the HFS service account has filesystem access outside the shared folder. Attackers can exploit the macro dispatcher's lack of authorization model combined with the path resolver's failure to confine absolute paths to manipulate the template engine and compromise the confidentiality, integrity, and availability of the host.
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-862Missing Authorization
Timeline
Published24 Sep 2026
Updated7 Oct 2026
First seen24 Sep 2026
Track software like this
Free during beta