
CVE-2026-36756 A Server-Side Request Forgery (SSRF) in the /plugins/-/install-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a craf… https://www.cve.org/CVERecord?id=CVE-2026-36756
Post summary
CVE‑2026‑36756 is an SSRF vulnerability in halo v2.22.14 that allows authenticated attackers to scan internal resources via the /plugins/-/install-from-uri endpoint; no PoC, exploit, patch, or active exploitation information is provided.


