CRITICAL 10.0 CVE-2026-97360 Published 24 Sept 2026

HFS2 Arbitrary File Access Vulnerability

Worried this affects your website?

HFS2 versions 2.4.0 and earlier contain an unauthenticated arbitrary file access vulnerability.

Attackers can read, write, append, and delete files anywhere the HFS service account has filesystem access outside the shared folder. The flaw is caused by the macro dispatcher's lack of an authorization model combined with the path resolver's failure to confine absolute paths.

  • Affected: HFS2 version 2.4.0 and earlier
  • Impact: read, write, append, and delete files outside the shared folder
  • Precondition: HFS service account has filesystem access to target files

This allows attackers to manipulate the template engine and compromise the confidentiality, integrity, and availability of the host.

Reference: CVE-2026-97360 on NVD

← Back to Security News