Remote Code Execution Vulnerability in Halo Software by Halo Dev
CVE-2026-67920

Currently unrated

Key Information:

Vendor

Halo Dev

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-67920?

A vulnerability in Halo version 2.25.4 enables remote attackers to exploit certain components, specifically the MigrationServiceImpl.restoreWorkdir() and org.springframework.util.FileSystemUtils.copyRecursively(), to execute arbitrary code. This security flaw allows unauthorized users to manipulate sensitive data and compromise the integrity of the application, making it critical for users to update to the latest version to mitigate potential risks.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.