Vulnerability record

CVE-2026-61500

Severity: CriticalExploitation: No known exploitation

Patch status

No official fix confirmed yet

Until a fix ships, follow the vendor's mitigations, limit exposure of affected systems, and watch this record for a patch.

Description

Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login. A remote attacker can collect a small number of login responses, reconstruct the generator's state, recover the signing key, and forge a valid administrator session cookie, leading to full administrative access and remote code execution via the server_code configuration feature.

Source: NIST National Vulnerability Database. Official vulnerability data, reproduced as published.

Intelligence timeline

Developments from the last 30 days, newest first.

  1. CVSS scoredUpdate

    CVE-2026-61500 scored CVSS 9.3

    Basis: NIST National Vulnerability Database

Coverage

We have not published a story about this vulnerability yet.

References

  • github.com https://github.com/rejetto/hfs/releases/tag/v3.2.1
  • vulncheck.com https://www.vulncheck.com/advisories/rejetto-hfs-session-forgery-via-predictable-signing-key