CVE-2026-49952

CRITICAL NUCLEI

Discuz! X5.0 Authentication Bypass via dbbak.php Encryption Oracle

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2026-49952. PoCs published by banyamer, CerberusMrXi, passwa11. A Nuclei detection template is also available.

AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in Discuz! X5.0 by leveraging an encryption oracle in UC_KEY to reuse tokens. The PoC obtains an authcode via a crafted login request and uses it to access dbbak.php, granting unauthorized database backup access.

Description

Discuz! X5.0 releases 20260320 through 20260501 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to gain unauthorized access to database backup and restore functionality by exploiting a shared cryptographic key between UCenter integration and the database backup API exposed by dbbak.php. Attackers can inject a crafted payload through the username parameter during login to abuse the encryption oracle in logging_ctl::logging_more(), obtain a legitimately signed token, and use it to bypass authorization for database export and import operations, with the additional ability to trigger a race condition to impersonate arbitrary users.

Exploits (3)

exploitdb WORKING POC
by banyamer · pythonwebappsmultiple
https://www.exploit-db.com/exploits/52621

This exploit demonstrates an authentication bypass vulnerability in Discuz! X5.0 by leveraging an encryption oracle in UC_KEY to reuse tokens. The PoC obtains an authcode via a crafted login request and uses it to access dbbak.php, granting unauthorized database backup access.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Discuz! X5.0 (versions 20260320 to 20260501)
No auth needed
Prerequisites: Target must be running Discuz! X5.0 (affected versions) · dbbak.php must be accessible · UC_KEY encryption oracle must be exploitable
mistral-large-3 · analyzed Jul 08, 2026 Full analysis →
github WORKING POC
by CerberusMrXi · poc
https://github.com/CerberusMrXi/Discuz-X5.0-Authentication-Bypass-Exploit-Framework

This exploit targets CVE-2026-49952, an authentication bypass vulnerability in Discuz! X5.0 that allows unauthenticated attackers to gain access via UC_KEY encryption oracle token reuse. The PoC includes version detection, target reconnaissance, and exploit execution capabilities.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Discuz! X5.0
No auth needed
Prerequisites: Discuz! X5.0 installation (versions between 20260320 - 20260501) · Network access to the target · Python 3.x environment for the exploit
mistral-large-3 · analyzed Jul 24, 2026 Full analysis →
github WORKING POC
by passwa11 · poc
https://github.com/passwa11/CVE-2026-49952

This repository contains a functional exploit for CVE-2026-49952, targeting Discuz! X5.0. The exploit demonstrates a remote code execution (RCE) chain involving database export/import, race condition attacks, and admin authentication bypass to achieve a webshell.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Racy
Target: Discuz! X5.0
No auth needed
Prerequisites: Pillow · torch · torchvision · access to target Discuz! instance
mistral-large-3 · analyzed Jun 17, 2026 Full analysis →

Nuclei Templates (1)

Discuz! X5.0 - Authentication Bypass
CRITICALVERIFIEDby 0x_Akoko
Shodan: http.html:"Discuz! X5.0"
FOFA: body="Discuz! X5.0"

Scores

CVSS v3 9.1
EPSS 0.0419
EPSS Percentile 90.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-323
Status published
Products (1)
Discuz!/Discuz! X5.0 20260320 - 20260501
Published Jun 15, 2026
Tracked Since Jun 16, 2026