LazyOwn vulnerability

LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn ships default C2 credentials LazyOwn and LazyOwn in payload.json and core/payload_schema.py and passes them unchanged to lazyc2.py HTTP Basic authentication, allowing any network-reachable attacker who knows the defaults to authenticate to the C2 dashboard with operator-level access. This issue is fixed in 0.2.154.

Published 30 Jul 2026Updated 10 Sep 20264 sources
CVSS 9.8

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.