CVE-2026-16088: halo-dev halo Files Backup Endpoint MigrationEndpoint.java download path traversal
A vulnerability was detected in halo-dev halo up to 2.24.2. Affected by this vulnerability is the function Download of the file MigrationEndpoint.java of the component Files Backup Endpoint. Performing a manipulation results in path traversal. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16088?
The severity of CVE-2026-16088 is classified as medium with a score of 4.7.
How do I fix CVE-2026-16088?
To fix CVE-2026-16088, upgrade to halo-dev halo version 2.24.3 or later, which addresses the path traversal vulnerability.
What component is affected in CVE-2026-16088?
The affected component in CVE-2026-16088 is the Files Backup Endpoint, specifically the Download function in MigrationEndpoint.java.
Does CVE-2026-16088 allow for remote exploitation?
Yes, CVE-2026-16088 can be exploited remotely through path traversal manipulation.
What type of attack does CVE-2026-16088 involve?
CVE-2026-16088 involves a path traversal attack that allows unauthorized access to files.