CVE-2026-3214: Arnabdotorg Captcha

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA allows Functionality Bypass.This issue affects CAPTCHA: from 0.0.0 before 1.17.0, from 2.0.0 before 2.0.10.

Affected products

  • Arnabdotorg Captcha: before 8.x-1.17 (fixed in 8.x-1.17); from 2.0.0, before 2.0.10 (fixed in 2.0.10)

Published 2026-03-25. Last modified 2026-06-17.