Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-49952— Discuz! X5.0 Authentication Bypass via dbbak.php Encryption Oracle

CVSS 9.1 · Critical EPSS 4.19% · P90

Public Exploits 2

ExploitDB · 1 EDB-52621 [webapps]

Affected Version Matrix 1

VendorProductVersion RangeStatus
Discuz!Discuz! X5.020260320≤ 20260501affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-49952

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Discuz! X5.0 Authentication Bypass via dbbak.php Encryption Oracle
Source: CVE Program / CVE List V5
Vulnerability Description
Discuz! X5.0 releases 20260320 through 20260501 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to gain unauthorized access to database backup and restore functionality by exploiting a shared cryptographic key between UCenter integration and the database backup API exposed by dbbak.php. Attackers can inject a crafted payload through the username parameter during login to abuse the encryption oracle in logging_ctl::logging_more(), obtain a legitimately signed token, and use it to bypass authorization for database export and import operations, with the additional ability to trigger a race condition to impersonate arbitrary users.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
在加密中重用Nonce与密钥对
Source: CVE Program / CVE List V5
Vulnerability Title
Discuz! X5.0 加密问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Discuz! X5.0是Discuz!团队的一款PHP网络论坛程序。 Discuz! X5.0存在加密问题漏洞,该漏洞源于UCenter集成与dbbak.php数据库备份API之间共享加密密钥,可能导致未经身份验证的远程攻击者在登录时通过username参数注入特制有效载荷,滥用logging_ctl::logging_more()中的加密预言机获取合法签名令牌,从而绕过数据库导出和导入操作的授权,并触发竞争条件冒充任意用户。以下版本受到影响:20260320版本至20260501版本。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Discuz!Discuz! X5.0 20260320 ~ 20260501 -

II. Public POCs for CVE-2026-49952

#POC DescriptionSource LinkShenlong Link
1Discuz! X5.0 20260320 through 20260501 contains an authentication bypass caused by exploitation of a shared cryptographic key and encryption oracle in dbbak.php and logging_ctl::logging_more(), letting unauthenticated remote attackers access database backup and restore functions, exploit requires crafted payload injection via username parameter. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-49952.yamlPOC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-49952

登录查看更多情报信息。

Patches & Fixes for CVE-2026-49952 (1)

Vendor Advisories for CVE-2026-49952 (1)

Other References for CVE-2026-49952 (1)

Same Patch Batch · Discuz! · 2026-06-15 · 3 CVEs total

CVE-2026-499547.2 HIGHDiscuz! X5.0 Local File Inclusion via enable_disable.php Plugin Directory
CVE-2026-499536.5 MEDIUMDiscuz! X5.0 CAPTCHA Bypass via Predictable Character Set

IV. Related Vulnerabilities

V. Comments for CVE-2026-49952

No comments yet


Leave a comment