{"id":"CVE-2026-81168","title":"Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass","summary":"Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue affects CAPTCHA Protected Page versions: from 0.0.0 to 1.0.2.","severity":"low","cvss":3.7,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-288"],"vendor":"captcha_protected_page_project","product":"captcha_protected_page","affected":["captcha_protected_page < 1.0.2"],"patched":["captcha_protected_page 1.0.2"],"published":"2026-09-02","updated":"2026-09-09","sourceUpdated":"2026-09-09T18:53:36.033","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-81168","references":[{"url":"https://www.drupal.org/sa-contrib-2026-105","label":"mlhess@drupal.org"}],"tags":["nvd"],"epss":0.00319,"epssPercentile":0.2504,"ingestedAt":"2026-09-09T19:19:51.815Z","slug":"CVE-2026-81168","body":"## Overview\n\nAuthentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue affects CAPTCHA Protected Page versions: from 0.0.0 to 1.0.2.\n\n## Affected\n\n- `captcha_protected_page < 1.0.2`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `captcha_protected_page 1.0.2`","depth":"sunlit","depthScore":20,"depthScoreParts":{"impact":20.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}