CVE-2026-61504: Rejetto HFS < 3.2.1 Stored XSS via File Names in Basic Web Listing
Rejetto HFS 3.0.0 through 3.2.0 does not escape file names in its fallback "basic" web listing, and this listing can be forced by any browser via the ?get=basic parameter. A user with upload permission - or an anonymous user on servers with an open upload folder - can store a file whose name contains script that executes in the browser of anyone viewing the listing.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61504?
The severity of CVE-2026-61504 is classified as medium with a score of 5.4.
How do I fix CVE-2026-61504?
To fix CVE-2026-61504, upgrade Rejetto HFS to version 3.2.1 or later.
What type of vulnerability is CVE-2026-61504?
CVE-2026-61504 is a stored cross-site scripting (XSS) vulnerability.
Who is affected by CVE-2026-61504?
Users of Rejetto HFS versions 3.0.0 through 3.2.0 with upload permissions are affected by CVE-2026-61504.
What conditions are required to exploit CVE-2026-61504?
CVE-2026-61504 can be exploited by users with upload permissions or anonymous users on servers with an open upload folder.