{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/halohub/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-67919"},{"id":"CVE-2026-67920"},{"id":"CVE-2026-67921"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Halo"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Halohub"],"content_html":"\u003cp\u003eResearchers have disclosed a chain of vulnerabilities in the Halo CMS (up to version 2.25.4) that facilitates remote code execution (RCE). The primary vulnerability, CVE-2026-67919, stems from the plugin installation and upgrade feature, which fetches and executes arbitrary JAR files from a user-supplied URL without verifying the source or destination. This is compounded by CVE-2026-67920, an insecure migration restore function that allows attackers to overwrite system extension directories, and CVE-2026-67921, a CSRF/CORS vulnerability that allows an attacker to bypass authentication requirements. By tricking an authenticated administrator into visiting a malicious webpage, an attacker can trigger the plugin or migration primitives, leading to full server-side code execution. Given the availability of public proof-of-concept (PoC) code and the high CVSS score (9.8), organizations running Halo should prioritize patching or restricting access to the console until a fix is deployed.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker constructs a malicious plugin JAR file containing arbitrary Java code and hosts it on an externally accessible web server.\u003c/li\u003e\n\u003cli\u003eAttacker hosts a malicious webpage (CSRF/CORS trigger) that, when visited by an administrator, performs cross-origin fetch requests to the Halo instance console.\u003c/li\u003e\n\u003cli\u003eThe victim administrator, who is already authenticated to the Halo console, visits the attacker-controlled webpage.\u003c/li\u003e\n\u003cli\u003eThe browser automatically includes the victim's session cookies with the request to the Halo API due to permissive CORS settings and 'SameSite=None' cookies.\u003c/li\u003e\n\u003cli\u003eThe attacker-controlled JavaScript executes an 'install-from-uri' or 'upgrade-from-uri' call to the Halo Plugin Manager API, pointing to the malicious JAR hosted in step 1.\u003c/li\u003e\n\u003cli\u003eThe Halo server fetches the malicious JAR from the attacker's server and proceeds to load and execute the contained Java classes within the application runtime.\u003c/li\u003e\n\u003cli\u003eThe attacker's code runs with the privileges of the Halo application service, allowing for persistent backdoor installation or full system compromise.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated remote attackers to achieve full code execution on the server hosting the Halo instance. This leads to complete system compromise, including the potential for data exfiltration, system destruction via the migration restore mechanism (which wipes existing configurations), and lateral movement within the target environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately restrict network access to the Halo administration console to trusted internal IP addresses only.\u003c/li\u003e\n\u003cli\u003eAudit all currently installed plugins in the Halo instance to ensure they match known, legitimate sources.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious POST requests to the \u003ccode\u003e/api/plugins/install-from-uri\u003c/code\u003e or \u003ccode\u003e/api/plugins/upgrade-from-uri\u003c/code\u003e endpoints, specifically those originating from external, unexpected hosts.\u003c/li\u003e\n\u003cli\u003eIf a fix is not immediately available, use firewall or WAF rules to block access to the \u003ccode\u003e/api/plugins/\u003c/code\u003e and \u003ccode\u003e/api/migration/\u003c/code\u003e endpoints from external sources.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-19T16:41:07Z","date_published":"2026-08-19T16:41:07Z","id":"https://feed.craftedsignal.io/briefs/2026-08-halo-rce-chain/","summary":"Halo versions up to 2.25.4 are vulnerable to RCE through insecure plugin installation and migration restoration processes, which can be chained with CSRF to allow unauthenticated attackers to compromise an instance if an administrator visits a malicious page.","title":"Remote Code Execution in Halo via Plugin and Migration Vulnerabilities","url":"https://feed.craftedsignal.io/briefs/2026-08-halo-rce-chain/"}],"language":"en","title":"CraftedSignal Threat Feed - Halohub","version":"https://jsonfeed.org/version/1.1"}