CVE-2026-61500 in Rejetto HFS: forged admin session and RCE without login
Rejetto HFS 3.0.0–3.2.0 carries a critical flaw (CVSS 9.8): a weak Math.random() in Koa lets attackers recover the cookie-signing key, forge an admin session and run code as root via server_code. Exploitation began October 1, 2026; HFS 3.2.1 fixes it.
- CVSS 3.1 score 9.8, CVSS 4.0 9.3, CWE-338 weak PRNG
- Six loginSrp1 requests leak V8 xorshift128+ state
- Forged cookie returns HTTP 200 on admin endpoints without login
- HFS 3.2.1 swaps Math.random() for randomBytes(32) and randomUUID()
Read next
Security