CVE-2026-36757: SSRF
A Server-Side Request Forgery (SSRF) in the /plugins/{name}/upgrade-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-36757?
The severity of CVE-2026-36757 is rated as medium with a CVSS score of 4.3.
What is CVE-2026-36757?
CVE-2026-36757 is a Server-Side Request Forgery (SSRF) vulnerability in the /plugins/{name}/upgrade-from-uri endpoint of Halo v2.22.14.
How can CVE-2026-36757 be exploited?
CVE-2026-36757 can be exploited by authenticated attackers using a specially crafted GET request to scan internal resources.
How do I fix CVE-2026-36757?
To mitigate CVE-2026-36757, ensure that no unauthorized access to the /plugins/{name}/upgrade-from-uri endpoint is allowed.
What is the impact of CVE-2026-36757?
The impact of CVE-2026-36757 includes unauthorized internal resource scanning, which can lead to further exploitation.