CVE-2026-67921 | Halo CMS up to 2.25.4 CorsConfigurer.java cross-site request forgery

SecurityVulns

A vulnerability, which was classified as problematic, was found in Halo CMS up to 2.25.4. This issue affects some unknown processing of the file CorsConfigurer.java. The manipulation results in cross-site request forgery.

This vulnerability is known as CVE-2026-67921. It is possible to launch the attack remotely. No exploit is available.VulDB Recent EntriesRead More