Medium severity4.3NVD Advisory· Published Jul 13, 2026· Updated Jul 14, 2026
CVE-2026-61502
CVE-2026-61502
Description
Rejetto HFS 3.0.0 through 3.2.0 accepts state-changing API requests via the GET method and exempts GET requests from its anti-CSRF header check. A remote attacker can perform administrative actions including account creation and configuration changes leading to code execution - by causing a logged-in administrator's browser to navigate to a crafted URL, or without any credentials against default installations when the attack originates from the server's own machine.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.