CVE-2026-81168 PUBLISHED

CAPTCHA Protected Page - Moderately critical - Cookie Forgery - SA-CONTRIB-2026-105

Assigner: drupal
Reserved: 26.08.2026 Published: 02.09.2026 Updated: 02.09.2026

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue affects CAPTCHA Protected Page versions: from 0.0.0 to 1.0.2.

Product Status

Vendor Drupal
Product CAPTCHA Protected Page
Versions
  • affected from 0.0.0 to 1.0.2 (excl.)

Credits

  • lovasoa finder
  • Carlo Miguel Agno (carlagno) remediation developer
  • Mark Jayson Gruta (mjgruta) remediation developer
  • Swan Kalata (akalata) coordinator
  • Carlo Miguel Agno (carlagno) coordinator
  • Greg Knaddison (greggles) coordinator
  • Heine Deelstra (heine) coordinator
  • Juraj Nemec (poker10) coordinator
  • Jess (xjm) coordinator

References

Problem Types

  • CWE-288 Authentication Bypass Using an Alternate Path or Channel CWE

Impacts

  • CAPEC-554 Functionality Bypass