HTB Layover Writeup | RDP to Craft CMS RCE (CVE-2026-44011) to Root via CUPS (CVE-2026-34990)
Hack The Box Layover overview: RDP entry, Wireshark credential sniffing, Craft CMS RCE (CVE-2026-44011), security-key decryption and CUPS privesc.
Due to Hack The Box policies this walkthrough is not publicly served until Layover retires. See the official HTB writeup guidelines.
Machine profile
- Platform
- Hack The Box
- Machine
- Layover
- Difficulty
- Medium
- Published
- Status
- active
Layover is a medium-difficulty Linux machine from Hack The Box, themed around the internal network of a corporate airport. Rather than a single service, the box is built as a workplace: several hosts, several trust levels, and the assumption that being inside the building means you are trusted.
The skills it belongs to are internal network enumeration, web application security, credential hygiene and Linux privilege escalation. What makes it interesting is the combination — the machine is designed so that no single mistake wins the box, and progress depends on noticing which of the ordinary details of a working environment are actually out of place.
It is a good fit for readers who have finished the single-service web boxes and want something that feels closer to a real corporate network, where the hard part is piecing together small observations rather than exploiting one obvious flaw. Expect to spend time reading output carefully rather than guessing at payloads, and expect the writeup to reward that habit once the box retires.
What this machine covers
Vulnerabilities
Software, services & tooling
Techniques & attack classes
What the finished writeup contains
When Layover retires, the complete walkthrough publishes here unchanged — every command, output and screenshot from the actual box, in the order it was solved.
- Reconnaissance Port scanning, service fingerprinting and attack-surface mapping
- Initial foothold The first authenticated or unauthenticated execution path
- Enumeration Deeper inspection of the exposed services and their configuration
- Exploitation Chaining the weaknesses found into a working exploit
- Credential recovery Secrets, keys and hashes, and how they were obtained
- Privilege escalation The route from the foothold account to a root shell
- Flags User and root flag capture
292 views on this machine so far — demand is tracked, and the walkthrough publishes the moment the box retires.
Why is this walkthrough protected right now?
No active-machine solution, flag, credential, exploit chain or private asset appears on this public page. Only the machine's profile, the topics it covers and a description of what the finished writeup will contain are published while the box is live.
Topics: RDP, Wireshark, Credential Sniffing, Craft CMS, CVE-2026-44011, Authenticated RCE, CVE-2026-34990, CUPS, OpenPrinting CUPS, Linux Privilege Escalation, Lateral Movement, Nmap
Comments
No comments yet — be the first to share your thoughts.