CVE-2026-105324
ADM HTTP Header Injection Vulnerability Allows Arbitrary File Read
Halo Surface Signal: 5 out of 5 — more likely to be public-facing.
An HTTP header injection vulnerability in ADM allows unauthenticated remote attackers to read arbitrary system files by sending crafted HTTP requests. This impacts ADM systems, potentially those facing the internet, and requires confirmation of system exposure and business criticality for remediation planning.