Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-97360: HFS2 allows outsiders to read, change, delete any file

CVE-2026-97360 · published 16 days ago
Summary

Versions of HFS2 up to 2.4.0 let anyone on the network read, modify, add to, or delete files that the HFS service can reach, even outside the shared folder. This can expose private data, corrupt information, or disrupt operations. Upgrade to a newer release or apply the vendor’s patch and limit the service account’s file permissions to reduce the risk.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
rejetto hfs2 <= 2.4.0
Original advisory text
HFS2 2.4.0 Unauthenticated Arbitrary File Read/Write via Template Engine
HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the HFS service account has filesystem access outside the shared folder. Attackers can exploit the macro dispatcher's lack of authorization model combined with the path resolver's failure to confine absolute paths to manipulate the template engine and compromise the confidentiality, integrity, and availability of the host.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
10.0 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-862Missing Authorization
Timeline
Published24 Sep 2026
Updated7 Oct 2026
First seen24 Sep 2026
Sources
CVE-2026-97360 · MITRE
Track software like this
Free during beta