CVE-2026-78971
NONE—CVSS v3
—CVSS v2
—
EPSS (exploit probability)
—CWE
Description
In Halo <= 2.25.4, the plugin management feature allows users to install/update malicious plugins, which could let attackers execute any command with Halo process permissions.
Affected routers (0)
No routers currently mapped to this CVE in our database.