Authentication Bypass Vulnerability in Drupal CAPTCHA
CVE-2026-3214
6.5MEDIUM
What is CVE-2026-3214?
An authentication bypass vulnerability exists in the Drupal CAPTCHA module that allows attackers to bypass intended security checks. This flaw could enable unauthorized access to functionalities that are designed to be restricted, affecting versions before 1.17.0 and 2.0.10. Administrators should ensure they are using an updated version of CAPTCHA to mitigate potential risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
CAPTCHA 0.0.0 < 1.17.0
CAPTCHA 2.0.0 < 2.0.10
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Andrew Wang (andrew.wang)
Andrew Belcher (andrewbelcher)
Chris Dudley (dudleyc)
M Parker (mparker17)
tamasd
Tim Wood (timwood)
Denis K**** (dench0)
Joshua Sedler (grevil)
Jakob P (japerry)
Adam Nagy (joevagyok)
cilefen (cilefen)
Damien McKenna (damienmckenna)
Greg Knaddison (greggles)
Lee Rowlands (larowlan)
Michael Hess (mlhess)
Juraj Nemec (poker10)
Jess (xjm)
