HackTheBox
Retired
4 notes

Fireflow
Unauthenticated Langflow RCE (CVE-2026-33017), internal MCP JWT alg:none confusion, and Kubernetes nodes/proxy pivot to root.

Absolute
AS-REP roasting, credential extraction from reversed binaries, BloodHound escalation via Certipy, and KrbRelay to Domain Admin.

Principal
Web authentication bypass via CVE-2026-29000, then credential harvesting and SSH certificate forgery to root.

Overwatch
Initial access via exposed MSSQL, SQL linked-server poisoning for credentials, and SYSTEM compromise via SOAP injection.