Writeups from Day 2 of SRCTF 2026, held on 16/08/2026

Challenges

  • This Seems Odd - IDOR in the patient roster exposes a hidden high-value patient
  • I See You - the record endpoint’s base64 ref lets you read the high-value patient’s record PDF
  • I’ll Be Reading That - XXE in the eRx prescription import leaks the .env with the Flask session signing key
  • The Auditor - GraphQL alias ordering bypass leaks the diagnostic token, unlocking command injection on the worker

Back to SRCTF 2026

4 items under this folder.