CVE-2026-49953
Discuz! X5.0 releases 20260320 through 20260501 contains a CAPTCHA bypass vulnerability that allows unauthenticated remote attackers to defeat challenge controls by exploiting limited complexity and predictable character sets in generated CAPTCHA images. Attackers can train a custom optical character recognition model against collected CAPTCHA samples to reliably predict challenge text, bypassing protections on login, registration, and other functionality from automated abuse.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.36%
- CWE
- CWE-804
- Published
- 2026-06-15
- Last modified
- 2026-07-28
Affected products
- Discuz! Discuz! X5.0
Weakness type
Related vulnerabilities
- CVE-2024-23566 — HCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha...
- CVE-2024-23567 — HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows...
- CVE-2026-13082 — GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets
- CVE-2026-40935 — WWBN/AVideo has CAPTCHA Bypass via Attacker-Controlled Length Parameter and Missing Token Invalidation on Failure
- CVE-2026-27411 — WordPress SiteGuard WP plugin plugin <= 1.7.9 - Captcha Bypass vulnerability
- CVE-2025-10423 — newbee-mall kaptcha mallKaptcha Captcha
- CVE-2025-8546 — atjiu pybbs Verification Code login Captcha
- CVE-2025-40916 — Mojolicious::Plugin::CaptchaPNG version 1.05 for Perl uses a weak random number source for generating the captcha text