CRITICAL 10.0 CVE-2026-97359 Published 24 Sept 2026

HFS2 Template Injection Vulnerability Allows Remote Code Execution

Worried this affects your website?

HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler.

Unauthenticated attackers can achieve remote code execution by embedding malicious template syntax in a filename. A crafted filename containing a closing template quoting sequence followed by an exec macro bypasses the authorization check in the dispatcher and executes arbitrary commands on the underlying host system.

  • Affected versions: HFS2 2.4.0 and earlier
  • Attack vector: multipart upload handler via crafted filename
  • Impact: unauthenticated remote code execution

Reference: CVE-2026-97359 on NVD

← Back to Security News