SB2026100630 - Multiple vulnerabilities in HFS



SB2026100630 - Multiple vulnerabilities in HFS

Published: October 6, 2026

Security Bulletin ID SB2026100630
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 6
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 67% Low 33%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 6 vulnerabilities.


1) Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) (CVE-ID: CVE-2026-61500)

CWE-ID: CWE-338 - Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

CVSSv4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to forge authenticated sessions.

The vulnerability exists due to use of predictable random values in session and login-handshake identifiers when generating session-related secrets. A remote attacker can predict application pseudorandom values to forge authenticated sessions.


2) Cross-site scripting (CVE-ID: CVE-2026-61501)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote attacker to execute arbitrary script in an administrator's browser.

The vulnerability exists due to improper neutralization of input during web page generation in the administrative log viewer when rendering failed-login log entries. A remote attacker can submit a failed login attempt containing malicious script content to execute arbitrary script in an administrator's browser.

User interaction is required to view the affected log entry.


3) Cross-site request forgery (CVE-ID: CVE-2026-61502)

CWE-ID: CWE-352 - Cross-Site Request Forgery (CSRF)

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized state-changing API operations.

The vulnerability exists due to improper cross-site request forgery protection in GET API handling when a browser sends a crafted GET request to a state-changing API. A remote attacker can trick a user into visiting a crafted URL to perform unauthorized state-changing API operations.


4) Path traversal (CVE-ID: CVE-2026-61505)

CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose information.

The vulnerability exists due to improper limitation of a pathname to a restricted directory in language-code handling when processing a crafted lang parameter. A remote attacker can send a request containing path traversal sequences to disclose information.


5) Cross-site scripting (CVE-ID: CVE-2026-61504)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary script in a victim's browser.

The vulnerability exists due to improper neutralization of input during web page generation in basic directory listings when rendering a crafted filename. A remote user can create a file with a malicious filename to execute arbitrary script in a victim's browser.

User interaction is required to view the affected basic directory listing.


6) Protection mechanism failure (CVE-ID: CVE-2026-61503)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass anti-brute-force login protections.

The vulnerability exists due to failure to invoke the failed-login event in the login API when handling an invalid username. A remote attacker can repeatedly submit login initiation requests with invalid usernames to bypass anti-brute-force login protections.

The issue affects plugin handling of failed login attempts for invalid usernames.


Remediation

Install update from vendor's website.