PT-2026-97806 · Hfs2 · Hfs2

·

CVE-2026-97360

·

Published

2026-09-24

·

Updated

2026-09-25

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HFS2 versions 2.4.0 and earlier
Description An unauthenticated arbitrary file access issue exists due to a lack of an authorization model in the macro dispatcher and a failure in the path resolver to confine absolute paths. This allows unauthenticated attackers to read, write, append, and delete files across any directory accessible by the HFS service account, extending beyond the intended shared folder. By manipulating the template engine, an attacker can compromise the confidentiality, integrity, and availability of the host system.
Recommendations Update HFS2 to a version later than 2.4.0.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-97360

Affected Products

Hfs2