SA-CONTRIB-2026-105: Critical severity drupal/captcha_protected_page vulnerability
This module enables site administrators to require CAPTCHA confirmation on specific pages. The module does not sufficiently validate its CAPTCHA verification cookies. Under certain circumstances, an unauthenticated user or automated bot can forge the cookie and bypass CAPTCHA verification entirely.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/captcha_protected_pageto a version that resolves this vulnerability.Fixed in 1.0.2
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated user or automated bot may be able to exploit the issue under certain circumstances by forging a CAPTCHA verification cookie.
What capability does an attacker need to bypass the CAPTCHA check?
The attacker needs to be able to forge the CAPTCHA verification cookie. No authenticated account is indicated as required.
Which protection can be bypassed if the issue is exploited?
CAPTCHA verification on pages configured by the module to require CAPTCHA confirmation can be bypassed entirely.