Intel

AIKIDO-2026-10250

drupal/captcha is vulnerable to Access bypass

Access bypassCVE-2026-3214 Published Feb 26, 2026

60

Medium Risk

This Affects:

PHPdrupal/captcha
0.0.1 - 1.16.0
Fixed in 1.17.0
2.0.0 - 2.0.9
Fixed in 2.0.10
Are you affected? Scan for Free

TL;DR

The module does not properly invalidate previously used security tokens in certain scenarios, allowing the CAPTCHA mechanism to be bypassed on subsequent submissions. Exploitation requires an attacker to first solve at least one CAPTCHA manually in order to obtain valid tokens.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

drupal/captcha is vulnerable to Access bypass in versions 0.0.1 - 1.16.0 and 2.0.0 - 2.0.9.

How to fix this

Upgrade the drupal/captcha library to the patch version.