OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-97359

CRITICAL · CVSS 10 EPSS 0.78% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

HFS2 versions 2.4.0 and earlier are vulnerable to a critical template injection flaw in the multipart upload handler, enabling unauthenticated attackers to execute arbitrary commands on the host system through crafted filenames. This vulnerability allows for remote code execution by bypassing authorization checks, posing a severe risk to systems running affected versions. Organizations using HFS2 should prioritize immediate patching or mitigation efforts to safeguard against potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-97359
Severity
CRITICAL
CVSS
10
EPSS
0.78%

Original NVD Description

HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated attackers to achieve remote code execution by embedding malicious template syntax in a filename. Attackers can craft a filename containing a closing template quoting sequence followed by an exec macro, which bypasses the authorization check in the dispatcher to execute arbitrary commands on the underlying host system.