A vulnerability was determined in Halo up to 2.21.10. This issue affects some unknown processing of the file /actuator of the component Configuration Handler. Executing a manipulation can lead to information disclosure. The attack may be performed from remote. This attack is characterized by high complexity. The exploitability is assessed as difficult. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
References
| Link | Resource |
|---|---|
| https://github.com/SECWG/cve/issues/9 | Issue Tracking |
| https://vuldb.com/?ctiid.338519 | Permissions Required VDB Entry |
| https://vuldb.com/?id.338519 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.715235 | Third Party Advisory VDB Entry |
Configurations
History
24 Feb 2026, 07:16
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) A vulnerability was determined in Halo up to 2.21.10. This issue affects some unknown processing of the file /actuator of the component Configuration Handler. Executing a manipulation can lead to information disclosure. The attack may be performed from remote. This attack is characterized by high complexity. The exploitability is assessed as difficult. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. |
19 Feb 2026, 15:46
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/SECWG/cve/issues/9 - Issue Tracking | |
| References | () https://vuldb.com/?ctiid.338519 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.338519 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.715235 - Third Party Advisory, VDB Entry | |
| CPE | cpe:2.3:a:halo:halo:*:*:*:*:*:*:*:* | |
| First Time |
Halo
Halo halo |
|
| CWE | NVD-CWE-noinfo |
28 Dec 2025, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-28 15:15
Updated : 2026-02-24 07:16
NVD link : CVE-2025-15141
Mitre link : CVE-2025-15141
CVE.ORG link : CVE-2025-15141
JSON object : View
Products Affected
halo
- halo
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
CWE-284Improper Access Control
NVD-CWE-noinfo