ZeroHour

Vulnerabilities

3 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-81168
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass.

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue affects CAPTCHA Protected Page versions: from 0.0.0 to 1.0.2.

NVD description · AI analysis pending
3.7<1%
  • captcha protected page project captcha protected page
CVE-2026-73476
Improper Handling of Case Sensitivity vulnerability in Drupal External Authentication allows Privilege Escalation.

Improper Handling of Case Sensitivity vulnerability in Drupal External Authentication allows Privilege Escalation. This issue affects External Authentication versions: from 0.0.0 to 2.0.13.

NVD description · AI analysis pending
5.4<1%
  • external authentication project external authentication
CVE-2026-66897
Path Traversal in Canonical LXD Template Processing Enables Host Root Compromise

CVE-2026-66897 is a path traversal flaw (CWE-22/CWE-23) in LXD's instance template processing: when handling target template paths declared in an image's metadata.yaml, LXD validates the path against a confined os.Root directory handle but then opens and creates the file with os.Create using an unconfined string path, so the check and the actual file creation can disagree. It is triggered by an authenticated user with permission to edit a container/instance, or by any user who launches an instance from a crafted image containing a malicious template path that escapes directory confinement. Successful exploitation lets the attacker overwrite arbitrary root-owned files on the LXD host and achieve host root code execution, consistent with the critical 9.9 CVSS score (network vector, low privileges, changed scope). The flaw affects Canonical LXD deployments, and it is most consequential on hosts where untrusted users hold container-edit rights or can import and launch images. Exploitation status: not listed in CISA KEV, EPSS estimates a ~0.6% probability of exploitation within 30 days (48th percentile), and one public advisory/PoC reference exists, so there is no confirmed in-the-wild exploitation at this time.

Do: Upgrade LXD to a patched release identified in Canonical's security advisory (GHSA-q39m-8fx9-42fv); the supplied data does not include fixed version numbers. Until patched, restrict container-edit permissions and image import/launch rights to trusted users and limit network exposure of the LXD API. Review hosts for untrusted users with instance-edit rights or use of third-party images, and verify the integrity of critical root-owned files.

9.9<1% PoC
  • Canonical LXD
moderatelikely on the order of 1,000–10,000 LXD hosts (estimate; no public install counts in the data)