Junglewise Threat Intelligence

CVE-2026-49952: Discuz! X5.0 authentication bypass in dbbak.php via token reuse

CVE-2026-49952 · Severity: critical · CVSS 9.1 · Published 2026-06-15

Technologies: Discuz! X. Vendors: Discuz!.

Executive brief

Discuz! X5.0, a popular forum and community platform, contains a security flaw in how it handles internal encryption keys. An unauthenticated attacker can exploit this to gain unauthorized access to the website's database backup and restore tools. This could allow an attacker to steal sensitive user data, modify the site's database, or even take over administrative accounts, potentially leading to a full site compromise.

Technical details

Discuz! X5.0 (releases 20260320 through 20260501) suffers from a cross-context token reuse vulnerability due to the reuse of the global 'authkey' for both UCenter integration (UC_KEY) and the database backup API (dbbak.php). An unauthenticated remote attacker can exploit an encryption oracle in the logging_ctl::logging_more() method by injecting a crafted payload into the username parameter during a login request. This allows the attacker to obtain a legitimately signed token that is accepted by /api/db/dbbak.php, granting access to database export and import operations. Furthermore, this access can be leveraged to trigger a race condition for full user impersonation. The vulnerability is patched in release 20260510.

Affected products

  • Discuz! Discuz! X5.0 20260320 through 20260501

Timeline

  • 2026-04-27: disclosed: Vendor contacted by researcher
  • 2026-05-09: patched: Fix committed to Gitee repository
  • 2026-05-10: patched: Fixed version 20260510 released
  • 2026-06-15: advisory: Public disclosure and CVE assignment

References

Related threats