CVE-2026-91772 MEDIUM

CVE-2026-91772: Halo through 2.26.1 Open Redirect via Unvalidated URI Parameter

Vendor Halo-Dev
Product halo
Weakness CWE-601 · Open redirect
Published September 15, 2026
Last update September 15, 2026

CVSS base score

6.1/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

What the vulnerability does

01Description

Halo through 2.26.1 contains an open redirect vulnerability in the anonymous thumbnail endpoint that fails to validate the uri query parameter. Attackers can craft malicious links on the trusted Halo domain that redirect visitors to arbitrary external sites, enabling phishing attacks and abuse of redirect-based trust relationships.

Key dates

02Disclosure timeline

September 15, 2026 CVE published

Related vulnerabilities

04Related CVE