Summary
CVE-2026-97360 is a critical missing-authorization vulnerability (CWE-862) in Rejetto HFS2 (HTTP File Server, the legacy pre-Node.js codebase), affecting versions 2.0.0 through 2.4.0. The flaw allows a completely unauthenticated, remote attacker to read, write, append to, and delete arbitrary files anywhere the HFS process account can access on the underlying filesystem — not just inside the configured shared folder. The vulnerability carries a maximum CVSS v3.1 base score of 10.0.
Technical details
- Root cause: HFS2’s macro/template dispatcher, which processes file-operation directives such as
{.load.},{.save.},{.append.}, and{.delete.}, performs no authorization checks before executing the requested operation. - Contributing flaw: The internal path resolution function returns the supplied path unmodified whenever it contains no forward slash, allowing absolute filesystem paths (e.g.,
C:Windowswin.ini) to bypass the intended confinement to the shared directory. - Trigger conditions: An attacker submits a request that reaches HFS2’s template evaluation engine (for example via upload filename handling) and injects a file-operation macro referencing an absolute path.
- Attack vector: Network, no authentication or user interaction required.
- Impact: Full compromise of confidentiality, integrity, and availability of the host — arbitrary file read (information disclosure), arbitrary file write/append (which can be leveraged toward remote code execution), and arbitrary file deletion outside the shared directory.
Affected software
- Rejetto HFS2 (HTTP File Server, legacy Delphi/Pascal-based branch) versions 2.0.0 through 2.4.0, inclusive
- The newer Node.js-based HFS 3.x rewrite is a separate, actively maintained codebase and is not affected by this issue
Severity
- CVSS v3.1 Base Score: 10.0 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: No fixed release of HFS2 currently addresses this flaw. Discontinue use of HFS2 and migrate to the actively maintained HFS 3.x branch, which uses a different codebase.
- If migration is not immediately possible:
- Restrict network access to HFS2 instances to trusted internal hosts only (e.g., via firewall rules or VPN); do not expose HFS2 directly to the internet.
- Run the HFS2 service account with the minimum filesystem privileges necessary, limiting the blast radius of arbitrary file access.
- Monitor logs for requests containing macro syntax (e.g.,
{.load.},{.save.},{.append.},{.delete.}) combined with absolute file paths, and block such requests at a reverse proxy or WAF where feasible.

