Junglewise Threat Intelligence

CVE-2026-61502: Rejetto HFS CSRF in API via GET requests

CVE-2026-61502 · Severity: medium · CVSS 4.3 · Published 2026-07-13

Technologies: Rejetto HTTP File Server, Rejetto HFS (HTTP File Server). Vendors: Rejetto.

Executive brief

Rejetto HFS, a popular file-sharing server, contains a security flaw that allows unauthorized administrative actions. By tricking a logged-in administrator into clicking a malicious link, an attacker can change server settings or create new accounts. In some default setups, this could even allow an attacker to take full control of the server and execute malicious code.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in Rejetto HFS versions 3.0.0 through 3.2.0. The application's API incorrectly allows state-changing operations to be performed using HTTP GET requests, which are exempted from the anti-CSRF header validation mechanism. An attacker can exploit this by inducing an authenticated administrator to visit a specially crafted URL. Successful exploitation allows for administrative actions such as account creation and configuration changes, which can be further leveraged to achieve remote code execution. The vulnerability is patched in version 3.2.1.

Affected products

  • Rejetto HFS (HTTP File Server) 3.0.0 through 3.2.0

Timeline

  • 2026-07-13: advisory: NVD and VulnCheck published the advisory
  • 2026-07-13: patched: Version 3.2.1 released to address the vulnerability

References

Related threats