{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3ahalo_devhalo/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:halo_dev:halo:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-97182"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Halo (\u003c= 2.25.4, \u003c= 2.26.1)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","rce","webserver"],"_cs_type":"advisory","_cs_vendors":["halo-dev"],"content_html":"\u003cp\u003eA security vulnerability identified as CVE-2026-97182 affects Halo versions 2.25.4/2.26.1 and prior. The vulnerability resides within the ReplyNotificationSubscriptionHelper.java component, specifically related to the handling of Spring Expression Language (SpEL) expressions. An unauthenticated remote attacker can exploit this flaw by manipulating input parameters passed to the notification subscription function. Because the input is not properly neutralized, the application interprets the malicious input as a SpEL expression, which the underlying framework executes. This leads to arbitrary code execution on the server hosting the Halo instance. Publicly disclosed exploit code currently exists, and the vendor has not provided a responsive update to the disclosure. Defenders should prioritize isolating affected Halo instances or implementing strict input validation at the web application firewall (WAF) layer until patches are available.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows for unauthenticated remote code execution, which grants the attacker full control over the application server. This can lead to total system compromise, data exfiltration, or the deployment of persistent threats such as web shells or ransomware within the organization's network environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImplement strict input validation or request filtering on all traffic directed to the Halo API endpoints associated with notification subscriptions.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for HTTP requests containing common SpEL injection characters such as #{, }, T(, or Class.forName.\u003c/li\u003e\n\u003cli\u003eEnsure the application service account runs with the principle of least privilege, specifically limiting execution permissions and file system access.\u003c/li\u003e\n\u003cli\u003eBlock or restrict access to the Halo management interface from non-trusted networks until the vulnerability is addressed by the vendor.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-24T14:47:13Z","date_published":"2026-09-24T14:47:13Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-97182/","summary":"Halo versions 2.25.4/2.26.1 and prior contain a critical vulnerability in the SpEL Handler component, allowing remote unauthenticated attackers to achieve remote code execution through improper expression neutralization.","title":"Improper Neutralization Vulnerability in Halo SpEL Handler","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-97182/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:halo_dev:halo:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}