CVE-2026-81168: CAPTCHA Protected Page - Moderately critical - Cookie Forgery - SA-CONTRIB-2026-105
Published Sep 2, 2026
·Updated
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue affects CAPTCHA Protected Page versions: from 0.0.0 to 1.0.2.
Affected Software
2 affected components
Drupal CAPTCHA Protected Page>=0.0.0<=1.0.2
Captcha Protected Page Project Captcha Protected Page Drupal<1.0.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
CAPTCHA Protected Pageto a version that resolves this vulnerability.Fixed in 1.0.2Patch SA-CONTRIB-2026-105
Event History
Sep 2, 2026
CVE Published
via MITRE·12:32 PM
Data Sourced
via MITRE·12:32 PM
DescriptionWeakness
Data Sourced
via NVD·01:18 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Which releases should be treated as affected?
The affected range is Drupal CAPTCHA Protected Page versions 0.0.0 through 1.0.2, inclusive.
2
Does the available information confirm that versions newer than 1.0.2 are unaffected?
No. The provided scope identifies affected versions only through 1.0.2 and does not make a statement about later releases.
3
Are specific deployment conditions or configuration requirements for exploitation provided?
No. The available information does not specify required configuration, authentication state, attacker access level, or a temporary mitigation.