External risk intelligence

HFS2 Remote Code Execution via Filename Template Injection

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-97359

The vulnerability exists in a file upload handler within an HFS (HTTP File Server) application. Such software is commonly deployed to serve files over the internet, making the upload interface, and this endpoint, a standard part of its public-facing web service functionality.

Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in HFS, a file server technology, that could allow unauthorized code execution. The issue stems from how the server handles filenames during file uploads, potentially enabling attackers to run commands on the server. The main concern is confirming relevance and exposure.

  • Unauthenticated code execution via file uploads.
  • Affects file server technology commonly used externally.
  • Confirm relevance and exposure to affected systems.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can exploit this vulnerability by uploading a file with a specially crafted filename. This filename bypasses authorization checks, allowing malicious code embedded within it to be executed on the server.

  • No authentication required for access.
  • Malicious filename triggers template injection.
  • Remote code execution on the host system.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow unauthenticated attackers to execute arbitrary commands on the host system when they upload files with specially crafted filenames. The multipart upload handler is susceptible to template injection, enabling attackers to bypass authorization checks.

  • System commands could be executed.
  • Malicious filenames in uploads could trigger it.
  • Full control over the host system may occur.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability impacts HFS (HTTP File Server) instances that handle multipart uploads. The primary responsibility for addressing this likely falls to the infrastructure or platform team managing the HFS deployment, in coordination with the application owner if HFS is integrated into a larger business application. The immediate first step is to identify all HFS installations, confirm their exposure to the network, and assess business criticality to prioritize remediation efforts.

  • Ownership: Infrastructure or platform team.
  • Verify first: HFS deployment exposure and criticality.
  • Action: Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is HFS2 and what is it used for?

HFS2 (HTTP File Server) is a software application designed to facilitate file sharing and hosting over a network. It acts as a web server specifically optimized for managing file uploads and downloads, allowing users to make local files accessible via a browser-based interface.

How does CVE-2026-97359 allow remote code execution?

This vulnerability is a template injection flaw. The application mistakenly processes parts of a filename as executable instructions rather than simple text. By embedding specific macro syntax into a filename during a multipart upload, an attacker can trick the server into running arbitrary system commands, falling under the weakness class of Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336).

Do I need to be authenticated to trigger this flaw?

No. The vulnerability exists within the multipart upload handler, which processes requests without requiring prior login. It is important to note that simply visiting the server or performing standard administrative tasks does not trigger the bug; the exploit requires the specific action of uploading a file with a maliciously crafted filename.

Is my instance at risk if it is not exposed to the internet?

Halo Surface Signal indicates that HFS2 instances are commonly deployed as public-facing services for file sharing, which makes them highly accessible. While the vulnerability is network-reachable, systems restricted to internal-only networks face lower immediate risk compared to those directly reachable from the public internet.

What are the first steps to secure my HFS2 installation?

Begin by auditing your infrastructure to create an inventory of all HFS2 deployments. Determine which instances are accessible from the network and assess their business importance. Once mapped, coordinate with your infrastructure or platform teams to prioritize these servers for updates or security hardening based on their exposure and criticality.

References