CAPTCHA Protected Page - Moderately critical - Cookie Forgery - SA-CONTRIB-2026-105
View online: https://www.drupal.org/sa-contrib-2026-105 Project: CAPTCHA Protected Page [1] Date: 2026-August-26 Security risk: *Moderately critical* 12 ∕ 25 AC:Complex/A:None/CI:Some/II:None/E:Theoretical/TD:All [2] Vulnerability: Cookie Forgery Affected versions: <1.0.2 CVE IDs: CVE-2026-81168 Description: This module enables site administrators to require CAPTCHA confirmation on specific pages. The module does not sufficiently validate its CAPTCHA verification cookies. Under certain circumstances, an unauthenticated user or automated bot can forge the cookie and bypass CAPTCHA verification entirely. Solution: Install the latest version: * If you use the CAPTCHA Protected Page module, upgrade to CAPTCHA Protected Page 1.0.2 [3]. Reported By: * lovasoa [4] Fixed By: * Carlo Miguel Agno (carlagno) [5] * Mark Jayson Gruta (mjgruta) [6] Coordinated By: * Swan Kalata (akalata) [7] of the Drupal Security Team * Carlo Miguel Agno (carlagno) [8] * Greg Knaddison (greggles) [9] of the Drupal Security Team * Heine Deelstra (heine) [10] of the Drupal Security Team * Juraj Nemec (poker10) [11] of the Drupal Security Team * Jess (xjm) [12] of the Drupal Security Team ------------------------------------------------------------------------------ Contribution record [13] [1] https://www.drupal.org/project/captcha_protected_page [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/captcha_protected_page/releases/1.0.2 [4] https://www.drupal.org/u/lovasoa [5] https://www.drupal.org/u/carlagno [6] https://www.drupal.org/u/mjgruta [7] https://www.drupal.org/u/akalata [8] https://www.drupal.org/u/carlagno [9] https://www.drupal.org/u/greggles [10] https://www.drupal.org/u/heine [11] https://www.drupal.org/u/poker10 [12] https://www.drupal.org/u/xjm [13] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal....
participants (1)
-
security-news@drupal.org