CVE-2026-61500Critical· 9.8▾ AbyssalPoC availableRejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login. A remote attacker can collect …
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 53.9 · likelihood 0.2 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CVEORG
Last analysed / modified upstream
0.9%
1 GitHub repo (last check)
Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login. A remote attacker can collect a small number of login responses, reconstruct the generator's state, recover the signing key, and forge a valid administrator session cookie, leading to full administrative access and remote code execution via the server_code configuration feature.
hfs >= 3.0.0 < 3.2.1Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-61505Medium· 5.3Rejetto HFS < 3.2.1 Limited File Disclosure via Path Traversal in lang Parameter
CVE-2026-61501Medium· 6.1Rejetto HFS < 3.2.1 Stored XSS in Admin Log Viewer
CVE-2026-61503Medium· 5.3Rejetto HFS < 3.2.1 Username Enumeration via Login Response Differences
CVE-2026-61504Medium· 5.4Rejetto HFS < 3.2.1 Stored XSS via File Names in Basic Web Listing
CVE-2026-61502Medium· 4.3Rejetto HFS < 3.2.1 Cross-Site Request Forgery via GET Requests
CVE-2026-97362High· 7.5HFS2 version 2.4.0 and earlier contains a denial of service vulnerability that allows unauthenticated attackers to cause a complete and persistent loss of availability by sending a single crafted request