Authentication Bypass Vulnerability in CAPTCHA Protected Page by Drupal
CVE-2026-81168

Currently unrated

Key Information:

Vendor

Drupal

Vendor
CVE Published:
2 September 2026

What is CVE-2026-81168?

A vulnerability in the CAPTCHA Protected Page component of Drupal allows attackers to bypass authentication by exploiting an alternate path or channel. This flaw impacts versions 0.0.0 through 1.0.2, enabling unauthorized access and potentially compromising sensitive functionalities. It's crucial for users of affected versions to update to secure their installations, as attackers may exploit this issue to gain unapproved access.

Affected Version(s)

CAPTCHA Protected Page 0.0.0 < 1.0.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

lovasoa
Carlo Miguel Agno (carlagno)
Mark Jayson Gruta (mjgruta)
Swan Kalata (akalata)
Carlo Miguel Agno (carlagno)
Greg Knaddison (greggles)
Heine Deelstra (heine)
Juraj Nemec (poker10)
Jess (xjm)
.