Description
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA allows Functionality Bypass.This issue affects CAPTCHA: from 0.0.0 before 1.17.0, from 2.0.0 before 2.0.10.
Problem types
CWE-288 Authentication Bypass Using an Alternate Path or Channel
Product status
0.0.0 (semver) before 1.17.0
2.0.0 (semver) before 2.0.10
Credits
Andrew Wang (andrew.wang)
Andrew Belcher (andrewbelcher)
Chris Dudley (dudleyc)
M Parker (mparker17)
tamasd
Tim Wood (timwood)
Denis K**** (dench0)
Joshua Sedler (grevil)
Jakob P (japerry)
Adam Nagy (joevagyok)
cilefen (cilefen)
Damien McKenna (damienmckenna)
Greg Knaddison (greggles)
Lee Rowlands (larowlan)
Michael Hess (mlhess)
Juraj Nemec (poker10)
Jess (xjm)
References
www.drupal.org/sa-contrib-2026-015