CVE-2026-49952
Discuz! X5.0 releases 20260320 through 20260501 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to gain unauthorized access to database backup and restore functionality by exploiting a shared cryptographic key between UCenter integration and the database backup API exposed by dbbak.php. Attackers can inject a crafted payload through the username parameter during login to abuse the encryption oracle in logging_ctl::logging_more(), obtain a legitimately signed token, and use it to bypass authorization for database export and import operations, with the additional ability to trigger a race condition to impersonate arbitrary users.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 4.72%
- CWE
- CWE-323
- Published
- 2026-06-15
- Last modified
- 2026-07-28
Affected products
- Discuz! Discuz! X5.0
Weakness type
Related vulnerabilities
- CVE-2026-81341 — wolfEngine reuses the AES-CCM nonce on TLS 1.2 / DTLS 1.2 records
- CVE-2026-81020 — wolfEngine reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 record
- CVE-2026-81019 — wolfProvider reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 record
- CVE-2026-50577 — ePA 3.x Integration: AES-GCM Nonce Reuse via Frozen VAU Request Counter
- CVE-2026-17578 — Kong Event Gateway AES-GCM nonce reuse due to missing key rotation enforcement
- CVE-2026-21383 — Reusing a Nonce, Key Pair in Encryption in HLOS
- CVE-2026-59099 — Apereo CAS 7.3.0 < 8.0.0-RC6 - AES-GCM Nonce Reuse Information Disclosure
- CVE-2026-13602 — Session takeover vulnerability