C2 Framework Vulnerability in LazyOwn by Grisuno
CVE-2026-68503
9.8CRITICAL
What is CVE-2026-68503?
The LazyOwn C2 framework, developed by Grisuno, has a security vulnerability that involves the use of default credentials within its configuration files. Specifically, prior to version 0.2.154, the framework's payload.json and core/payload_schema.py files contained unchanged default C2 credentials, allowing any attacker with network access to gain operator-level access to the C2 dashboard. This issue has serious implications for security as it could allow unauthorized users to manipulate or exfiltrate sensitive data. Users are advised to upgrade to version 0.2.154 or later to mitigate this risk.
Affected Version(s)
LazyOwn < 0.2.154
