Cross-Site Request Forgery Vulnerability in Halo CMS by Halo Dev
CVE-2026-67921

Currently unrated

Key Information:

Vendor

Halo Dev

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-67921?

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in Halo CMS, specifically affecting versions up to 2.25.4. This vulnerability resides in the CorsConfigurer.java and CsrfConfigurer.java components and could potentially allow a remote attacker to execute arbitrary code on the server through malicious requests. Users of affected versions are advised to take immediate action to mitigate potential risks associated with this exploit.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.