SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-78971

MEDIUM · CVSS 4.6 EPSS 0.17% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The plugin management feature in Halo versions up to 2.25.4 is vulnerable, allowing users to install or update malicious plugins that can execute arbitrary commands with the permissions of the Halo process. This could lead to unauthorized access and control over the affected systems. Organizations using Halo should prioritize this vulnerability to mitigate potential exploitation risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-78971
Severity
MEDIUM
CVSS
4.6
EPSS
0.17%

Original NVD Description

In Halo <= 2.25.4, the plugin management feature allows users to install/update malicious plugins, which could let attackers execute any command with Halo process permissions.