CVE-2026-61501
Last modified
CVE-2026-61501 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. Rejetto HFS 3.0.0 through 3.2.0 renders log entries in the administration panel as HTML without sanitization. A remote unauthenticated attacker can submit a failed login with a crafted username that is written to the error log and executes JavaScript in an administrator's browser when the logs are viewed, allowing the attacker to create accounts or execute code on the server with the administrator's privileges.. EPSS estimates a 0.31% chance of exploitation in the next 30 days.
Description
Rejetto HFS 3.0.0 through 3.2.0 renders log entries in the administration panel as HTML without sanitization. A remote unauthenticated attacker can submit a failed login with a crafted username that is written to the error log and executes JavaScript in an administrator's browser when the logs are viewed, allowing the attacker to create accounts or execute code on the server with the administrator's privileges.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| rejetto | hfs | >= 3.0.0, < 3.2.1 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-61501?
How severe is CVE-2026-61501?
How do I fix CVE-2026-61501?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-61487Improper Authorization vulnerability in Apache ActiveMQ Brok…6.5
- CVE-2026-6149A flaw has been found in code-projects Vehicle Showroom Mana…7.3
- CVE-2026-61492In JetBrains YouTrack before 2026.2.17394 stored XSS via art…6.1
- CVE-2026-61498Vitec Flamingo 4.12.2 contains an unauthenticated OS command…9.8
- CVE-2026-6150A vulnerability has been found in code-projects Simple Laund…4.3
- CVE-2026-61500Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie s…9.8
- CVE-2026-61502Rejetto HFS 3.0.0 through 3.2.0 accepts state-changing API r…5.1
- CVE-2026-61503Rejetto HFS 3.0.0 through 3.2.0 returns observably different…6.9
- CVE-2026-61504Rejetto HFS 3.0.0 through 3.2.0 does not escape file names i…5.4
- CVE-2026-61505Rejetto HFS 3.0.0 through 3.2.0 allows path traversal throug…6.9
- CVE-2026-6151A vulnerability was found in code-projects Vehicle Showroom …7.3
- CVE-2026-61511vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains a…9.8
Are you affected by CVE-2026-61501?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
