Vendor
Halo versions 2.25.4/2.26.1 and prior contain a critical vulnerability in the SpEL Handler component, allowing remote unauthenticated attackers to achieve remote code execution through improper expression neutralization.