A Critical Flaw in Rejetto HFS Exposes Admin Sessions, Leaving Users Vulnerable to Remote Code Execution
Rejetto HFS, a popular file hosting solution used by millions worldwide, has been hit with a severe security vulnerability that allows attackers to forge admin sessions and execute remote code. The flaw, discovered in the server-side software, enables malicious actors to assume administrator privileges on affected systems, paving the way for devastating cyber attacks.
The issue lies in how Rejetto HFS handles user authentication, specifically in its handling of session cookies. When an admin logs into their account, a unique session ID is generated and stored on the client’s browser. However, due to a weakness in the software, attackers can manipulate this session cookie to gain unauthorized access to admin sessions. Furthermore, with admin privileges at hand, they can also execute arbitrary code on the affected server, leading to remote code execution (RCE) attacks.
The vulnerability affects all versions of Rejetto HFS up to version 3.1 and is particularly concerning due to its ease of exploitation. Attackers only need to manipulate the session cookie in a targeted user’s browser to gain admin access, making it an attractive attack vector for malicious actors seeking to compromise sensitive systems. Moreover, as Rejetto HFS is commonly used by businesses and organizations, this vulnerability puts thousands of users at risk.
The severity of this flaw cannot be overstated, and affected parties should take immediate action to mitigate the threat. Users are advised to update their Rejetto HFS installations to the latest version (3.2), which patches the critical flaw. Additionally, administrators should review and revise access controls to prevent unauthorized access to admin sessions.
In light of this vulnerability, it’s crucial for system administrators and users alike to prioritize security updates and patch management. Regularly reviewing software configurations, monitoring for suspicious activity, and keeping software up-to-date can significantly reduce the risk of a successful attack. As a general rule, whenever new vulnerabilities emerge, users should assume they are at risk until proven otherwise – in this case, until the affected systems have been patched and verified to be secure.
Source: The Hacker News — 2026-10-05