CVE-2026-61502Medium· 4.3▾ SunlitRejetto HFS 3.0.0 through 3.2.0 accepts state-changing API requests via the GET method and exempts GET requests from its anti-CSRF header check. A remote attacker can perform administrative actions including account creation and configur…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CVEORG
Last analysed / modified upstream
0.2%
Rejetto HFS 3.0.0 through 3.2.0 accepts state-changing API requests via the GET method and exempts GET requests from its anti-CSRF header check. A remote attacker can perform administrative actions including account creation and configuration changes leading to code execution - by causing a logged-in administrator's browser to navigate to a crafted URL, or without any credentials against default installations when the attack originates from the server's own machine.
hfs >= 3.0.0 < 3.2.1Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-61505Medium· 5.3Rejetto HFS < 3.2.1 Limited File Disclosure via Path Traversal in lang Parameter
CVE-2026-61501Medium· 6.1Rejetto HFS < 3.2.1 Stored XSS in Admin Log Viewer
CVE-2026-61503Medium· 5.3Rejetto HFS < 3.2.1 Username Enumeration via Login Response Differences
CVE-2026-61500Critical· 9.8Rejetto HFS < 3.2.1 Session Forgery via Predictable Signing Key
CVE-2026-61504Medium· 5.4Rejetto HFS < 3.2.1 Stored XSS via File Names in Basic Web Listing
CVE-2025-31963Low· 2.9Improper authentication and missing CSRF protection in the local setup interface component in HCL BigFix IVR version 4.2 allows a local attacker to perform unauthorized configuration changes via unauthenticated administrative configurati…