Cross-Site Request Forgery Vulnerability in Halo CMS by Halo Dev
CVE-2026-67921
Currently unrated
What is CVE-2026-67921?
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in Halo CMS, specifically affecting versions up to 2.25.4. This vulnerability resides in the CorsConfigurer.java and CsrfConfigurer.java components and could potentially allow a remote attacker to execute arbitrary code on the server through malicious requests. Users of affected versions are advised to take immediate action to mitigate potential risks associated with this exploit.
