Halo through 2.26.1 contains an open redirect vulnerability in the anonymous thumbnail endpoint that fails to validate the uri query parameter. Attackers can craft malicious links on the trusted Halo domain that redirect visitors to arbitrary external sites, enabling phishing attacks and abuse of redirect-based trust relationships.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-15 02:16
Updated : 2026-09-15 02:16
NVD link : CVE-2026-91772
Mitre link : CVE-2026-91772
CVE.ORG link : CVE-2026-91772
JSON object : View
Products Affected
No product.
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
