CVE-2026-91772: Halo through 2.26.1 Open Redirect via Unvalidated URI Parameter

Published Sep 15, 2026
·
Updated

Halo through 2.26.1 contains an open redirect vulnerability in the anonymous thumbnail endpoint that fails to validate the uri query parameter. Attackers can craft malicious links on the trusted Halo domain that redirect visitors to arbitrary external sites, enabling phishing attacks and abuse of redirect-based trust relationships.

Affected Software

1 affected component
Halo<=2.26.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Halo to a version that resolves this vulnerability.

    Fixed in 2.26.1
  2. Configuration

    Update Halo to a version that fixes the open redirect in the anonymous thumbnail endpoint by validating the uri query parameter so it cannot redirect to arbitrary external sites.

    Halo anonymous thumbnail endpoint uri query parameter validation = validated

Event History

Sep 15, 2026
CVE Published
via MITRE·01:20 AM
Data Sourced
via MITRE·01:20 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An unauthenticated attacker can craft a malicious link using the anonymous thumbnail endpoint. Exploitation requires convincing a visitor to follow that link.

2

Are default or public-facing deployments affected?

The affected endpoint is described as anonymous, so deployments that expose Halo's anonymous thumbnail endpoint may be susceptible without requiring the attacker to authenticate.

3

What is the practical impact?

The trusted Halo domain can be used to redirect visitors to an arbitrary external site. This can support phishing and bypasses of trust relationships that allow or rely on redirects from the Halo domain.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203