seclists.org
http://seclists.org/fulldisclosure/2026/Jun/4 CVE-2026-49953
MEDIUM
Discuz! X5.0 CAPTCHA Bypass via Predictable Character Set
Record summary
CVE-2026-49953 has a selected CVSS score of 6.9 (medium).
Description
Discuz! X5.0 releases 20260320 through 20260610 contains a CAPTCHA bypass vulnerability that allows unauthenticated remote attackers to defeat challenge controls by exploiting limited complexity and predictable character sets in generated CAPTCHA images. Attackers can train a custom optical character recognition model against collected CAPTCHA samples to reliably predict challenge text, bypassing protections on login, registration, and other functionality from automated abuse.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 15, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Discuz! X5.0Browse Discuz! / Discuz! X5.0Default status: unknown | CVE List | 20260320 to ≤ 20260610 | affected |
References
5karmainsecurity.comTechnical description
https://karmainsecurity.com/KIS-2026-10 karmainsecurity.comexploit
https://karmainsecurity.com/chaining-bugs-in-discuz-from-race-condition-to-rce nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-49953 vulncheck.comThird-party advisory
https://www.vulncheck.com/advisories/discuz-x5-0-captcha-bypass-via-predictable-character-set