What is CVE-2026-68503?
LazyOwn RedTeam/APT Framework versions prior to 0.2.154 contain hardcoded default C2 credentials (LazyOwn / LazyOwn) in payload.json and core/payload_schema.py. This flaw allows unauthorized network access to the framework via HTTP Basic Authentication. Immediate credential rotation and upgrading to the latest version is recommended.
Azərbaycanca: LazyOwn RedTeam/APT Framework-in 0.2.154 versiyasına qədər olan versiyalarında default C2 etimadnamələri (LazyOwn / LazyOwn) payload.json və core/payload_schema.py fayllarında saxlanılır. Bu boşluq HTTP Basic Authentication-u istismar edərək şəbəkə üzərindən çərçivəyə icazəsiz girişə imkan yaradır. Dərhal etimadnamələri yeniləmək və son versiyaya yüksəltmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-798
FAQ2
Which versions of the LazyOwn APT Framework are affected by CVE-2026-68503?
LazyOwn RedTeam/APT Framework versions prior to 0.2.154 are affected.
What can an attacker gain by exploiting CVE-2026-68503?
An attacker can gain unauthorized network access to the framework via HTTP Basic Authentication using the hardcoded default C2 credentials.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.