Cross-site scripting in HFS - CVE-2026-61501

 

Cross-site scripting in HFS - CVE-2026-61501

Published: October 6, 2026


Vulnerability identifier: #VU153315
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2026-61501
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary script in an administrator's browser.

The vulnerability exists due to improper neutralization of input during web page generation in the administrative log viewer when rendering failed-login log entries. A remote attacker can submit a failed login attempt containing malicious script content to execute arbitrary script in an administrator's browser.

User interaction is required to view the affected log entry.


Affected software

HFS

How to mitigate CVE-2026-61501

Install security update from vendor's website.

HFS - update to 3.2.1

External References

Related Security Bulletins