CVE-2026-61502: Rejetto HFS < 3.2.1 Cross-Site Request Forgery via GET Requests
Rejetto HFS 3.0.0 through 3.2.0 accepts state-changing API requests via the GET method and exempts GET requests from its anti-CSRF header check. A remote attacker can perform administrative actions including account creation and configuration changes leading to code execution - by causing a logged-in administrator's browser to navigate to a crafted URL, or without any credentials against default installations when the attack originates from the server's own machine.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61502?
The severity of CVE-2026-61502 is medium with a score of 4.3.
How do I fix CVE-2026-61502?
To fix CVE-2026-61502, upgrade Rejetto HFS to version 3.2.1 or later.
What type of attack does CVE-2026-61502 involve?
CVE-2026-61502 involves a Cross-Site Request Forgery (CSRF) attack via GET requests.
What are the risks associated with CVE-2026-61502?
The risks include unauthorized administrative actions such as account creation and configuration changes.
Which versions of Rejetto HFS are affected by CVE-2026-61502?
Rejetto HFS versions 3.0.0 through 3.2.0 are affected by CVE-2026-61502.