{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/discuz-x5.0-20260320-through-20260501/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-49952"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":["https://sploitus.com/exploit?id=E3511389-563B-5AD7-A686-6FA07D46FB08\u0026utm_source=rss\u0026utm_medium=rss"],"_cs_products":["Discuz! X5.0 (20260320 through 20260501)","Discuz! X5.0"],"_cs_severities":["high"],"_cs_tags":["authentication-bypass","web-vulnerability","cve","discuz","data-exfiltration"],"_cs_type":"advisory","_cs_vendors":["Discuz!"],"content_html":"\u003cp\u003eA critical authentication bypass vulnerability, identified as CVE-2026-49952, impacts Discuz! X5.0 releases from 20260320 through 20260501. This flaw allows unauthenticated remote attackers to gain unauthorized access to sensitive database backup and restore functionalities. The vulnerability stems from a shared cryptographic key utilized between the UCenter integration and the \u003ccode\u003edbbak.php\u003c/code\u003e database backup API. Attackers can leverage an encryption oracle within the \u003ccode\u003elogging_ctl::logging_more()\u003c/code\u003e function by injecting a specially crafted payload via the username parameter during a login attempt. This manipulation enables them to obtain a legitimately signed token, thereby circumventing standard authorization checks for database operations and potentially triggering a race condition to impersonate arbitrary users. This provides a direct path to sensitive data exfiltration and control over forum content.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated remote attacker identifies a Discuz! X5.0 instance (releases 20260320-20260501) vulnerable to CVE-2026-49952.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious payload and injects it into the \u003ccode\u003eusername\u003c/code\u003e parameter during a login attempt to the Discuz! instance via a \u003ccode\u003ePOST\u003c/code\u003e request to \u003ccode\u003e/member.php\u003c/code\u003e or similar login endpoint.\u003c/li\u003e\n\u003cli\u003eThis crafted payload is processed by the \u003ccode\u003elogging_ctl::logging_more()\u003c/code\u003e function, which contains an encryption oracle due to a shared cryptographic key used by UCenter integration.\u003c/li\u003e\n\u003cli\u003eBy exploiting this encryption oracle, the attacker obtains a legitimately signed authorization token that can bypass further access controls.\u003c/li\u003e\n\u003cli\u003eThe attacker uses the forged token to send direct HTTP requests to the \u003ccode\u003e/dbbak.php\u003c/code\u003e endpoint, bypassing normal authentication and authorization checks.\u003c/li\u003e\n\u003cli\u003eThrough the \u003ccode\u003e/dbbak.php\u003c/code\u003e interface, the attacker gains unauthorized access to initiate database export (backup) and import (restore) operations.\u003c/li\u003e\n\u003cli\u003eThe attacker can additionally trigger a race condition during this process to impersonate arbitrary authenticated users within the Discuz! forum.\u003c/li\u003e\n\u003cli\u003eThe final objective is unauthorized access to critical database functions, allowing for data theft, modification, or complete compromise of the forum's content and user data.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-49952 grants unauthenticated attackers full control over the Discuz! X5.0 application's database. This includes the ability to export all database contents, leading to mass data exfiltration of user information, private messages, and forum posts. Attackers could also import malicious data, deface the forum, or implant persistent backdoors. The ability to impersonate arbitrary users further exacerbates the risk, allowing attackers to perform actions as legitimate users, including administrative actions if an administrator account is impersonated. Organizations using affected Discuz! X5.0 versions face severe risks of data breach, reputational damage, and operational disruption.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ePatch CVE-2026-49952 immediately\u003c/strong\u003e by upgrading Discuz! X5.0 to a version beyond 20260501 that includes the fix.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rules \u0026quot;Detects CVE-2026-49952 Exploitation - Malicious Username Injection Attempt\u0026quot; and \u0026quot;Detects CVE-2026-49952 Exploitation - Unauthorized dbbak.php Access\u0026quot; to your SIEM to detect exploitation attempts.\u003c/li\u003e\n\u003cli\u003eEnable comprehensive webserver access logging to capture full HTTP request details (URI stem, query, method, user-agent) for your Discuz! instances to facilitate detection and forensics.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-24T19:00:31Z","date_published":"2026-06-15T20:19:42Z","id":"https://feed.craftedsignal.io/briefs/2026-06-discuz-auth-bypass/","summary":"CVE-2026-49952 is an authentication bypass vulnerability in Discuz! X5.0 versions 20260320 through 20260501, allowing unauthenticated remote attackers to gain unauthorized access to database backup and restore functionality by exploiting a shared cryptographic key, leading to potential data exfiltration and user impersonation.","title":"CVE-2026-49952: Discuz! X5.0 Authentication Bypass Leading to Database Access","url":"https://feed.craftedsignal.io/briefs/2026-06-discuz-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Discuz! X5.0 (20260320 Through 20260501)","version":"https://jsonfeed.org/version/1.1"}