MEDIUMVulnerability
CVE-2026-78971
In Halo <= 2.25.4, the plugin management feature allows users to install/update malicious plugins, which could let attackers execute any command with Halo process permissions.
Properties
- severity
- MEDIUM
- score
- 4.6
- cve_id
- CVE-2026-78971
- signal_observed_at
- 2026-09-17T21:32:19+00:00
- vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
- published_at
- 2026-09-08T21:18:42.130
- last_modified
- 2026-09-14T15:17:07.613
Related Entities (2)
HAS_WEAKNESS (1)
→[Weakness]Improper Control of Generation of Code ('Code Injection')
DESCRIBED_BY (1)
→[Source]NVD
Explore deeper with Ninja Signal's threat intelligence graph