CVE-2026-61500: Rejetto HFS Authentication Bypass and RCE
Score: 7/10

CVE-2026-61500: Rejetto HFS Authentication Bypass and RCE

An unauthenticated attacker can achieve remote code execution on Rejetto HFS by exploiting a predictable PRNG to forge administrator sessions.

Executive Summary

CVE-2026-61500 is a critical vulnerability (CVSS 9.3) affecting Rejetto HTTP File Server (HFS) versions 3.0.0 through 3.2.0. Discovered using Anthropic's Mythos AI through Project Glasswing, the flaw stems from the insecure use of JavaScript's `Math.random()` to generate session-signing secrets. By reconstructing the pseudo-random number generator (PRNG) state, attackers can forge valid administrator session cookies.

Technical analysis reveals a chain involving PRNG state recovery via unauthenticated information leakage, session forgery, and subsequent abuse of administrative APIs to execute arbitrary server-side JavaScript. This vulnerability moved from public disclosure by Horizon3.ai on September 30, 2026, to active exploitation in the wild by October 1, 2026.

Successful exploitation grants an attacker full host compromise. Organizations running affected versions are urged to upgrade to HFS 3.2.1 immediately, as typical remediation like password changes will not mitigate this session-forgery technique.

Key Details

Threat Name

CVE-2026-61500

Affects

Rejetto HTTP File Server (HFS) versions 3.0.0 through 3.2.0, Rejetto HFS, Rejetto HTTP File Server (HFS) 3.X, Rejetto HFS 2.X

Adversary

—

Malware/Tools

None identified

Report Score

7out of 10
Quality Score
Good
IOC Quality2
TTP Details9
Detection Guidance4
Enterprise Relevance6
Clarity & Structure8
Technical Depth9

Sources