SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-61503

MEDIUM · CVSS 5.3 EPSS 0.34% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

Rejetto HFS versions 3.0.0 to 3.2.0 are vulnerable due to their login endpoint revealing whether a submitted username is valid, which can be exploited by remote unauthenticated attackers to enumerate valid account names. This vulnerability increases the risk of password-guessing and session-forgery attacks, particularly targeting the default admin account. Organizations using affected versions should prioritize remediation to protect against potential unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-61503
Severity
MEDIUM
CVSS
5.3
EPSS
0.34%

Original NVD Description

Rejetto HFS 3.0.0 through 3.2.0 returns observably different responses from its login endpoint depending on whether the submitted username exists. A remote unauthenticated attacker can use this to confirm valid account names, including the default admin account, facilitating password-guessing and session-forgery attacks.