Server-Side Request Forgery Vulnerability in Halo Software by Halo Dev
CVE-2026-36759

6.5MEDIUM

Key Information:

Vendor

Halo Dev

Status
Vendor
CVE Published:
30 April 2026

What is CVE-2026-36759?

A vulnerability exists in the Halo software where an authenticated attacker can leverage the /themes/{name}/upgrade-from-uri endpoint to conduct Server-Side Request Forgery (SSRF) attacks. By crafting a malicious GET request, attackers can probe internal resources, potentially leading to unauthorized access or exposure of sensitive information. This highlights the importance of securing endpoints to protect against unauthorized internal network scans.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.