
Orion is a Linux machine compromised via a Craft CMS 5.6.16 RCE exploit for initial access as www-data, followed by credential extraction from a leaked .env file, database enumeration for a crackable admin hash, and privilege escalation to root through CVE-2026-24061, an authentication bypass in telnetd via a spoofed USER environment variable.

