External risk intelligence

HFS Arbitrary File Access Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-97360

HFS (HTTP File Server) is by design an internet-facing service intended to serve and manage files over the network. Because the vulnerability is unauthenticated and accessible via standard HTTP requests, it is designed to be reachable from the internet in its normal deployment role as a file-sharing gateway.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability affects the HFS file server technology, allowing unauthenticated attackers to potentially access, modify, or delete files anywhere the HFS service has permissions. This could compromise the confidentiality, integrity, and availability of the host system by manipulating the template engine.

  • Unauthorized file access and modification possible.
  • Critical impact on data confidentiality and integrity.
  • Confirm HFS relevance and exposure to assets.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can exploit a flaw in the macro dispatcher and path resolver of HFS2 to manipulate the template engine. This allows them to access, modify, or delete files outside the designated shared folder, potentially compromising the entire host system.

  • No authentication required for access.
  • Triggers via manipulating the template engine.
  • Risk of full host compromise.

Live Threat

Current exploitation, exposure, and threat context

The HFS service account's filesystem access could be compromised, allowing attackers to read, write, append, and delete files outside the designated shared folder. This could impact the confidentiality, integrity, and availability of the host system when the template engine is manipulated.

  • System files and service data at risk.
  • Unauthenticated network access allows file manipulation.
  • Host system compromise and data loss.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts HFS (HTTP File Server), which is typically deployed as an internet-facing service for file management. The first step is to identify all instances of HFS, confirm their network exposure and business criticality, and then assign ownership for remediation. This will involve coordination between application owners, infrastructure teams responsible for the HFS deployment, and potentially network or security teams to assess external access.

  • Identify HFS instances and ownership.
  • Verify network exposure and criticality.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is HFS2 and how is it used?

HFS2 (HTTP File Server) is a software application designed to facilitate file sharing and management over a network. It functions as a web-based portal where users can upload, download, and organize files, acting as a gateway for remote data access.

What is the vulnerability in CVE-2026-97360?

This vulnerability is an instance of CWE-862, or missing authorization. In plain terms, the software fails to verify if a user has permission to perform certain actions. By manipulating the template engine, an attacker can bypass restrictions to read, write, or delete files outside of the intended shared folder.

How does an attacker trigger this bug?

The flaw is triggered when an attacker sends specific HTTP requests that interact with the application's macro dispatcher and path resolver. The bug does not require authentication; however, file manipulation is constrained by the specific permissions assigned to the service account running the HFS software on the host system.

Is my instance of HFS2 at risk?

According to Halo Surface Signal, HFS is typically deployed as an internet-facing service to manage files remotely. Because the flaw is reachable via standard HTTP requests without authentication, any HFS2 instance accessible from the internet is considered highly relevant and carries a significant risk of unauthorized access.

What should I do if I run HFS2?

Begin by auditing your environment to locate all running instances of HFS2 and identifying who owns each deployment. Assess the network exposure of these instances and coordinate with your infrastructure and security teams to verify their criticality and prioritize them for remediation.

References