CVE-2026-67919: Halo Halo vulnerability
Published Aug 17, 2026
·Updated
An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.java, installFromUri method, and DefaultPluginApplicationContextFactory components
Affected Software
1 affected component
Halo Halo=2.25.4
Event History
Aug 17, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2026-67919?
CVE-2026-67919 is classified as a high-risk vulnerability with a severity score of 89.
2
What software is affected by CVE-2026-67919?
CVE-2026-67919 affects the Halo software in version 2.25.4.
3
How do I fix CVE-2026-67919?
To fix CVE-2026-67919, ensure that you update Halo to the latest version that addresses this vulnerability.
4
What type of vulnerability is CVE-2026-67919?
CVE-2026-67919 is a code execution vulnerability that allows remote attackers to execute arbitrary code.
5
What components are involved in CVE-2026-67919?
CVE-2026-67919 involves the PluginEndpoint.java and DefaultPluginApplicationContextFactory components.