CVE-2026-61502: Rejetto HFS

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Rejetto HFS 3.0.0 through 3.2.0 accepts state-changing API requests via the GET method and exempts GET requests from its anti-CSRF header check. A remote attacker can perform administrative actions including account creation and configuration changes leading to code execution - by causing a logged-in administrator's browser to navigate to a crafted URL, or without any credentials against default installations when the attack originates from the server's own machine.

Affected products

  • Rejetto HFS: from 3.0.0, before 3.2.1 (fixed in 3.2.1)

Published 2026-07-13. Last modified 2026-07-14.