Junglewise Threat Intelligence

CVE-2026-49953: Discuz! X5.0 CAPTCHA bypass via predictable character set

CVE-2026-49953 · Severity: medium · CVSS 6.5 · Published 2026-06-15

Technologies: Discuz! X. Vendors: Discuz!.

Executive brief

Discuz! X5.0, a popular forum and community platform, contains a security weakness in its CAPTCHA system. This system is designed to distinguish human users from automated bots during registration and login. Because the CAPTCHA images are too simple and predictable, attackers can use automated tools to solve them, allowing for large-scale automated abuse such as account takeovers, spam, or fake account creation.

Technical details

A CAPTCHA bypass vulnerability exists in Discuz! X5.0 (releases 20260320 through 20260610) due to the use of a predictable character set and limited image complexity. This weakness allows an unauthenticated remote attacker to collect CAPTCHA samples and train a custom Optical Character Recognition (OCR) model to reliably solve the challenges. By bypassing these controls, attackers can automate interactions with protected endpoints such as login, registration, and posting forms. This vulnerability was notably used as a component in a larger exploit chain to automate a race condition attack leading to remote code execution. As of the advisory date, no official patch has been released.

Affected products

  • Discuz! Discuz! X5.0 20260320 through 20260610

Timeline

  • 2026-03-20: other: Discuz! X5.0 initial release date
  • 2026-04-27: other: Vendor first contacted by researcher
  • 2026-05-09: other: Vendor acknowledges OCR-based bypass as a known issue
  • 2026-06-09: other: CVE identifier assigned
  • 2026-06-13: disclosed: Public disclosure at hackmeeting 0x1D
  • 2026-06-15: advisory: Publication of security advisory KIS-2026-10

References

Related threats