CVE-2026-97360: HFS2 2.4.0 Unauthenticated Arbitrary File Read/Write via Template Engine
HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the HFS service account has filesystem access outside the shared folder. Attackers can exploit the macro dispatcher's lack of authorization model combined with the path resolver's failure to confine absolute paths to manipulate the template engine and compromise the confidentiality, integrity, and availability of the host.
Affected Software
Event History
Frequently Asked Questions
Which deployments should be treated as exposed?
Deployments running Rejetto HFS2 version 2.4.0 or earlier should be treated as exposed if an attacker can reach the HFS service. The affected file scope is limited by the filesystem permissions of the account running HFS, but includes locations outside the configured shared folder.
Does an attacker need credentials or user interaction to exploit this issue?
No. The issue is described as unauthenticated, with network access, low attack complexity, and no required user interaction.
What level of host impact is possible?
An attacker can read, write, append to, and delete files wherever the HFS service account has filesystem access. This can compromise confidentiality, integrity, and availability of the host.