CVE-2026-97360
Last modified
CVE-2026-97360 is a critical-severity vulnerability rated 10/10 on the CVSS scale. HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the HFS service account has filesystem access outside the shared folder. Attackers can exploit the macro dispatcher's lack of authorization model combined with the path resolver's failure to confine absolute paths to manipulate the template engine and compromise the confidentiality, integrity, and availability of the host..
Description
HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the HFS service account has filesystem access outside the shared folder. Attackers can exploit the macro dispatcher's lack of authorization model combined with the path resolver's failure to confine absolute paths to manipulate the template engine and compromise the confidentiality, integrity, and availability of the host.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| rejetto | hfs2 | >= 2.0.0, <= 2.4.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-97360?
How severe is CVE-2026-97360?
How do I fix CVE-2026-97360?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-97326A weakness has been identified in songxinjianqwe Chat up to …7.3
- CVE-2026-9733Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17…9.1
- CVE-2026-9734The W3SC Elementor to Zoho CRM plugin for WordPress is vulne…4.3
- CVE-2026-9735MongoDB server may log authentication parameters, including …6.8
- CVE-2026-97359HFS2 version 2.4.0 and earlier contains a template injection…10
- CVE-2026-9736IBM Netezza Software 11.3.0.3 through Interim Fix 002 could …4.3
- CVE-2026-97362HFS2 version 2.4.0 and earlier contains a denial of service …7.5
- CVE-2026-97365A vulnerability was determined in chonkie-inc littrs 0.6.1/0…6.3
- CVE-2026-97366A security flaw has been discovered in jhen0409 react-native…6.3
- CVE-2026-97368A weakness has been identified in chillzhuang SpringBlade up…6.3
- CVE-2026-9737During query planning when reading the sort pattern in raw B…7.1
- CVE-2026-9738The Print, PDF, Email by PrintFriendly plugin for WordPress …4.4
Are you affected by CVE-2026-97360?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
