PT-2026-60931 · Halo Dev · Halo

·

CVE-2026-16088

·

Published

2026-07-18

·

Updated

2026-07-20

CVSS v2.0

5.8

Medium

VectorAV:N/AC:L/Au:M/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions halo-dev halo versions prior to 2.24.3
Description A path traversal issue exists in the Files Backup Endpoint component within the Download() function of the MigrationEndpoint.java file. This flaw allows a remote attacker to perform manipulations that enable unauthorized access to files and directories outside the intended folder.
Recommendations Update halo-dev halo to version 2.24.3 or later. As a temporary mitigation, restrict access to the Download() function in the MigrationEndpoint.java file.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16088

Affected Products

Halo