CVE-2026-49952
CRITICAL NUCLEIDiscuz! X5.0 Authentication Bypass via dbbak.php Encryption Oracle
Title source: cnaExploitation Summary
EIP tracks 3 public exploits for CVE-2026-49952. PoCs published by banyamer, CerberusMrXi, passwa11. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in Discuz! X5.0 by leveraging an encryption oracle in UC_KEY to reuse tokens. The PoC obtains an authcode via a crafted login request and uses it to access dbbak.php, granting unauthorized database backup access.
Description
Discuz! X5.0 releases 20260320 through 20260501 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to gain unauthorized access to database backup and restore functionality by exploiting a shared cryptographic key between UCenter integration and the database backup API exposed by dbbak.php. Attackers can inject a crafted payload through the username parameter during login to abuse the encryption oracle in logging_ctl::logging_more(), obtain a legitimately signed token, and use it to bypass authorization for database export and import operations, with the additional ability to trigger a race condition to impersonate arbitrary users.
Exploits (3)
This exploit demonstrates an authentication bypass vulnerability in Discuz! X5.0 by leveraging an encryption oracle in UC_KEY to reuse tokens. The PoC obtains an authcode via a crafted login request and uses it to access dbbak.php, granting unauthorized database backup access.
This exploit targets CVE-2026-49952, an authentication bypass vulnerability in Discuz! X5.0 that allows unauthenticated attackers to gain access via UC_KEY encryption oracle token reuse. The PoC includes version detection, target reconnaissance, and exploit execution capabilities.
This repository contains a functional exploit for CVE-2026-49952, targeting Discuz! X5.0. The exploit demonstrates a remote code execution (RCE) chain involving database export/import, race condition attacks, and admin authentication bypass to achieve a webshell.
Nuclei Templates (1)
http.html:"Discuz! X5.0"
body="Discuz! X5.0"
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N