---
id: CVE-2026-97360
title: >-
  HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file
  access vulnerability that allows unauthenticated attackers to read, write,
  append, and delete files anywhere the HFS service account has filesystem
  access outside …
summary: >-
  HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file
  access vulnerability that allows unauthenticated attackers to read, write,
  append, and delete files anywhere the HFS service account has filesystem
  access outside …
severity: critical
cvss: 10
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-862
vendor: rejetto
product: hfs2
affected:
  - hfs2 >= 2.0.0 <= 2.4.0
published: '2026-09-24'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T16:17:29.283'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-97360'
references:
  - url: >-
      https://github.com/wgetnz/hfs2/blob/master/advisories/hfs2-template-macro-missing-authorization/README.md
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/hfs2-unauthenticated-arbitrary-file-read-write-via-template-engine
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-24T14:58:41.458904Z'
ingestedAt: '2026-09-24T13:43:25.672Z'
---

## Overview

HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the HFS service account has filesystem access outside the shared folder. Attackers can exploit the macro dispatcher's lack of authorization model combined with the path resolver's failure to confine absolute paths to manipulate the template engine and compromise the confidentiality, integrity, and availability of the host.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
