← Back to search

CVE-2026-97359

10 CRITICALpublic exploit available

Published 2026-09-24 · Updated 2026-09-29

AI risk analysis

Summary
HFS2 version 2.4.0 and earlier is vulnerable to remote code execution via a template injection flaw in the multipart upload handler, allowing unauthenticated attackers to execute arbitrary commands on the host system.
Exploitability
Exploitation is relatively straightforward as it requires crafting a specific filename to bypass authorization checks. Attackers must have network access to the affected HFS2 instance.
Blast radius
If exploited, this vulnerability could result in complete compromise of the host system, leading to data loss, system corruption, or unauthorized access to sensitive information.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to HFS2 version 2.5.0 or later.
rcewebauth-bypass

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated attackers to achieve remote code execution by embedding malicious template syntax in a filename. Attackers can craft a filename containing a closing template quoting sequence followed by an exec macro, which bypasses the authorization check in the dispatcher to execute arbitrary commands on the underlying host system.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-1336

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.