CVE-2026-68503

LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn ships default C2 credentials LazyOwn and LazyOwn in payload.json and core/payload_schema.py and passes them unchanged to lazyc2.py HTTP Basic authentication, allowing any network-reachable attacker who knows the defaults to authenticate to the C2 dashboard with operator-level access. This issue is fixed in 0.2.154.
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-30 21:18

Updated : 2026-09-10 20:12


NVD link : CVE-2026-68503

Mitre link : CVE-2026-68503

CVE.ORG link : CVE-2026-68503


JSON object : View

Products Affected

No product.

CWE
CWE-1392

Use of Default Credentials