CVE-2026-78971: Halo Halo vulnerability
Published Sep 8, 2026
·Updated
In Halo <= 2.25.4, the plugin management feature allows users to install/update malicious plugins, which could let attackers execute any command with Halo process permissions.
Affected Software
1 affected component
Halo Halo<=2.25.4
Event History
Sep 8, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
Which deployments are affected?
Halo versions 2.25.4 and earlier are affected where the plugin management feature can be used to install or update plugins.
2
What does an attacker need to exploit this issue?
An attacker needs the ability to install or update a malicious plugin through Halo's plugin management feature. Successful exploitation can execute commands with the permissions of the Halo process.
3
What is the impact of successful exploitation?
A malicious plugin can cause arbitrary command execution with the same permissions assigned to the Halo process. The resulting access level depends on how that process is configured to run.