CVE-2026-36758: SSRF
A Server-Side Request Forgery (SSRF) in the /themes/-/install-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-36758?
CVE-2026-36758 has been classified as a high severity vulnerability due to its potential for exploitation by attackers to access internal resources.
How does CVE-2026-36758 work?
CVE-2026-36758 functions by allowing authenticated attackers to send crafted GET requests to the /themes/-/install-from-uri endpoint, enabling them to perform Server-Side Request Forgery attacks.
How do I fix CVE-2026-36758?
To fix CVE-2026-36758, update Halo to the latest version that addresses this vulnerability, or restrict access to the affected endpoint.
Who is affected by CVE-2026-36758?
CVE-2026-36758 affects any deployment of Halo version 2.22.14 that has the vulnerable endpoint exposed.
What are the consequences of exploiting CVE-2026-36758?
Exploiting CVE-2026-36758 can lead to unauthorized access to internal resources, potentially compromising sensitive data or system integrity.