← Back to CVE List
Vulnerability Intelligence Report
HFS2 2.4.0 Unauthenticated Arbitrary File Read/Write via Template Engine

CVE-2026-97360

x_open-sourceunsupported-when-assigned

HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the HFS service account has filesystem access outside the shared folder. Attackers can exploit the macro dispatcher's lack of authorization model combined with the path resolver's failure to confine absolute paths to manipulate the template engine and compromise the confidentiality, integrity, and availability of the host.

No Active Exploit Signals
CVSS Base Score
10.0
CRITICAL
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-862 ↗Missing Authorization

Affected Products & Versions

Vendor Product Affected Versions
rejetto hfs2 2.0.0 <= 2.4.0 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityVulnCheck · Bug Bounty Provider · USA
Reserved2026-09-24T13:29:26
Published2026-09-24T13:32:32
Patch Date2026-09-24
Last Updated2026-09-24T15:00:30

LINK COPIED TO CLIPBOARD