CVE-2026-67921 is a Cross-Site Request Forgery vulnerability affecting Halo CMS versions up to and including 2.25.4. The issue is associated with the CorsConfigurer.java and CsrfConfigurer.java components, indicating improper or insufficient request-origin and CSRF protection handling in security-related request processing. Successful exploitation could allow a remote attacker to cause the application to process unauthorized requests in the context of an authenticated victim session, ultimately leading to arbitrary code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
The repository contains a README and three standalone browser PoCs; it does not use an exploit framework. It claims CVE-2026-67921 in Halo CMS <= 2.25.4, a combined configuration flaw where API paths use permissive credentialed CORS and are excluded from CSRF protection. Each PoC automatically executes on page load against the hard-coded private target 192.168.49.128:8090 and reports HTTP responses in the page. The change-password PoC uses XMLHttpRequest with credentials to set the admin password to hacked123. The create-user PoC uses fetch with credentials to create hacker/hacker123 and request super-role. The plugin PoC requests installation of a JAR hosted at attacker.com, which may become RCE if plugins are trusted and executed. The README also documents conceptual content-modification and form-based attacks, remediation guidance, and the alleged vulnerable Java configuration paths. The attack is operational but hard-coded: an operator must replace the target and attacker plugin URL and satisfy the target's authentication, authorization, cookie, CORS, and network conditions.
Repository contains a working exploit set for Halo plugin-install/upgrade and migration-restore vulnerabilities, plus a malicious plugin payload. The structure is split into: exploit/ (Python and browser exploit clients), plugin/ (Java PF4J-style malicious plugin and build script), and notes/ (research/verification details). Main capabilities are: (1) authenticated admin RCE by POSTing an arbitrary JAR URL to install-from-uri, then enabling the plugin; (2) one-request RCE by upgrading an existing plugin from an attacker-controlled URL with matching metadata.name and higher version; (3) browser-only CSRF/CORS chain that performs the same actions from a victim admin’s browser without XSRF validation; and (4) migration restore abuse that causes Halo to fetch an arbitrary ZIP and restore it, with destructive overwrite effects and write-into-workdir behavior. The Python login helper automates Halo’s login flow by scraping /login for _csrf and the RSA public key, encrypting the password client-side equivalent, then establishing a session. The malicious Java plugin is straightforward and operational: it executes shell commands via sh -c in both a static initializer and a @PostConstruct method, writing proof files under /tmp. The build script fetches PF4J/Jakarta dependencies from Maven Central and packages the plugin with META-INF/plugin-components.idx and plugin.yaml. Overall, this is a real exploit repository, not a detector: it provides end-to-end exploitation for Halo admin-to-RCE and SSRF-like arbitrary fetch primitives, with a destructive migration restore PoC as well.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.