Cross-site scripting in HFS - CVE-2026-61501
Published: October 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary script in an administrator's browser.
The vulnerability exists due to improper neutralization of input during web page generation in the administrative log viewer when rendering failed-login log entries. A remote attacker can submit a failed login attempt containing malicious script content to execute arbitrary script in an administrator's browser.
User interaction is required to view the affected log entry.