Drupal CAPTCHA Protected Page Auth Bypass v0.0.01.0.2 (Alt Path)
CVE-2026-81168 Published on September 2, 2026
CAPTCHA Protected Page - Moderately critical - Cookie Forgery - SA-CONTRIB-2026-105
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue affects CAPTCHA Protected Page versions: from 0.0.0 to 1.0.2.
Vulnerability Analysis
CVE-2026-81168 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality, a small impact on integrity and availability.
Weakness Type
Authentication Bypass Using an Alternate Path or Channel
A product requires authentication, but the product has an alternate path or channel that does not require authentication.
Affected Versions
Drupal CAPTCHA Protected Page:- Version 0.0.0 and below 1.0.2 is affected.