C2 Framework Vulnerability in LazyOwn by Grisuno
CVE-2026-68503

9.8CRITICAL

Key Information:

Vendor

Grisuno

Status
Vendor
CVE Published:
30 July 2026

What is CVE-2026-68503?

The LazyOwn C2 framework, developed by Grisuno, has a security vulnerability that involves the use of default credentials within its configuration files. Specifically, prior to version 0.2.154, the framework's payload.json and core/payload_schema.py files contained unchanged default C2 credentials, allowing any attacker with network access to gain operator-level access to the C2 dashboard. This issue has serious implications for security as it could allow unauthorized users to manipulate or exfiltrate sensitive data. Users are advised to upgrade to version 0.2.154 or later to mitigate this risk.

Affected Version(s)

LazyOwn < 0.2.154

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.