EIP-2026-106589

PRE-CVE

Drupal Module CAPTCHA - Security Bypass

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-106589. PoCs published by anonymous.

AI-analyzed exploit summary This PoC demonstrates a CAPTCHA bypass vulnerability in the Drupal CAPTCHA module, allowing brute-force attacks by reusing session tokens after solving the CAPTCHA once. It automates login attempts with a predefined password list while handling anti-XSRF tokens dynamically.

Description

Drupal Module CAPTCHA - Security Bypass

Exploits (1)

exploitdb WORKING POC VERIFIED
by anonymous · htmlwebappsphp
https://www.exploit-db.com/exploits/35335

This PoC demonstrates a CAPTCHA bypass vulnerability in the Drupal CAPTCHA module, allowing brute-force attacks by reusing session tokens after solving the CAPTCHA once. It automates login attempts with a predefined password list while handling anti-XSRF tokens dynamically.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Drupal CAPTCHA module (version not specified)
No auth needed
Prerequisites: Valid initial session tokens (cookie, captcha_sid, captcha_token, form_build_id) · Solved CAPTCHA challenge once to initiate the session
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026