S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Jul 29, 2026

CVE-2026-49952 Scanner

CVE-2026-49952 Scanner - Authentication Bypass vulnerability in Discuz! X5.0

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-49952
9.3
CVSScritical
Exploitable remotely over the internet · no authentication required.

Discuz! X5.0 releases 20260320 through 20260501 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to gain unauthorized access to database backup and restore functionality by exploiting a shared cryptographic key between UCenter integration and the database backup API exposed by dbbak.php. Attackers can inject a crafted payload through the username parameter during login to abuse the encryption oracle in logging_ctl::logging_more(), obtain a legitimately signed token, and use it to bypass authorization for database export and import operations, with the additional ability to trigger a race condition to impersonate arbitrary users.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Discuz! X5.0by Discuz!
20260320
Updated Aug 19, 2026View on NVD →
Detail

Discuz! X5.0 is a widely used forum software developed by Comsenz Technology, primarily deployed by online communities seeking efficient forum management. Organizations and individuals utilize Discuz! X5.0 to establish and manage online discussion boards, providing features that encourage user interaction. The platform is popular among users due to its extendable and customizable architecture, allowing for plugin integration and theme customization. Discuz! X5.0 is commonly used in environments requiring structured conversation management and a scalable user-interface for community interaction. It also serves as a powerful tool for educational institutions, companies, and enthusiasts looking to create an engaging user community. Software like Discuz! X5.0 often requires regular updates and maintenance to address security vulnerabilities.

The Authentication Bypass vulnerability in Discuz! X5.0 allows unauthorized remote attackers to exploit shared cryptographic keys and encryption oracle vulnerabilities. Through dbbak.php and logging_ctl::logging_more(), attackers can bypass authentication, gaining unauthorized access to critical functions. Additionally, crafted payloads manipulated via the username parameter enable exploitation of this vulnerability, circumventing normal security controls. This vulnerability poses a significant risk by allowing attackers to execute database export and import actions. The confidentiality and integrity of the Discuz! X5.0 implementation are severely compromised. This issue is particularly concerning when the software is publicly accessible without patched updates.

The technical details of the vulnerability involve a shared cryptographic key and encryption oracle in the Discuz! X5.0 framework. Remote attackers can inject a crafted payload through the dbbak.php endpoint, utilizing the username parameter to bypass authentication measures. The vulnerable endpoint is typically exposed in default installations without specific patches. Attackers can manipulate logging_ctl::logging_more() to facilitate arbitrary database interactions. The authentication bypass allows the execution of code that affects database backup and restore functions. Security assessments have shown that this vulnerability offers a straightforward exploit vector, given the necessary conditions.

When exploited, the vulnerabilities can have several detrimental effects. Unauthorized entities could perform complete database compromises, leading to data breaches and information theft. Attackers might alter or erase database contents, affecting the integrity of user data. The exploitation of this vulnerability can result in compromised user accounts and administrative control losses. Unmitigated, it poses threats to sensitive information safeguarding and disrupts normal service provisions. Furthermore, the exploitation might lead to reputational damage for entities relying on Discuz! X5.0 for community management, diminishing trust among users.

REFERENCES

Solution Advice
  • Update Discuz! X5.0 installations to a version later than 20260501 or use the latest available version.
  • Regularly inspect and rotate cryptographic keys to prevent shared key vulnerabilities.
  • Implement additional authentication layers such as multi-factor authentication to mitigate bypass risks.
  • Conduct frequent security assessments and vulnerability scans on the Discuz! X5.0 environment.
  • Restrict access to critical administrative functions and monitor logs for unauthorized access attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.