PT-2026-66608 · Lazyown · Lazyown

CVE-2026-68502

·

Published

2026-07-30

·

Updated

2026-07-31

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LazyOwn RedTeam/APT Framework versions prior to 0.2.154
Description LazyOwn is an AI-powered C2 and red-team operations framework. The lazyc2.py component registers an unauthenticated Socket.IO input event handler that dispatches the value variable to the one cmd() function, which subsequently reaches do cmd() and subprocess.call(command, shell=True). This sequence allows an unauthenticated user to achieve remote code execution within the C2 process.
Recommendations Update to version 0.2.154.

Exploit

Fix

RCE

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-68502
GHSA-FR84-8CFG-59W4

Affected Products

Lazyown