CVE-2026-49952 is an authentication bypass vulnerability affecting Discuz! X5.0 releases 20260320 through 20260501. In standalone-mode deployments, the application initializes the UCenter cryptographic key from the global authentication key, causing the same secret to be reused across unrelated security contexts. This breaks cryptographic isolation between UCenter integration and the database backup and restore interface exposed by dbbak.php. An unauthenticated remote attacker can abuse login-related processing in logging_ctl::logging_more() as an encryption oracle by supplying crafted input through the username parameter during a login request. The attacker can thereby obtain a legitimately signed token that is accepted by the database backup API, bypassing its authorization checks and gaining access to database export and import operations. The issue also enables exploitation of a race condition during restore-related workflows that can be used to impersonate arbitrary users.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository is a standalone Python exploit framework for the claimed Discuz! X5.0 authentication bypass vulnerability CVE-2026-49952. It is not tied to a common exploitation framework like Metasploit or Nuclei. The repository is small and centered on a single executable script, exploit.py, supported by a README and requirements file. Structure: LICENSE, README.md, exploit.py, and requirements.txt. The main logic resides in exploit.py, which exposes a CLI with options for target URL, proxy, verbosity, output file, thread count, interactive mode, custom payload, timeout, and color control. The script appears intended for direct execution as a standalone operator tool. Capabilities: The exploit performs Discuz fingerprinting/version detection, checks for known Discuz paths, attempts to determine whether the target is vulnerable, and then runs an authentication bypass workflow. Based on the README and visible code, the bypass abuses token generation/validation tied to UC_KEY and reuses a crafted token to access the database backup endpoint. The tool supports multi-payload attacks, threaded execution, session handling, proxying, SSL/TLS connections, interactive shell mode, and result export. This makes it more than a simple detector; it is an operational exploit automation tool. Targeting: The code and README consistently target Discuz! X5.0, especially builds/releases between 2026-03-20 and 2026-05-01. The primary target endpoint is /api/db/dbbak.php, while member.php is referenced as part of the login/token acquisition flow. Additional fingerprinting paths include /data/install.lock, /source/discuz_version.php, /source/class/discuz/discuz_application.php, /admin.php, /static/js/common.js, and /uc_server/. Assessment: This is a real exploit-oriented repository rather than a README-only project or a pure scanner. The payload is not a post-exploitation shell; instead it is an auth-bypass/token-manipulation payload that grants unauthorized access to sensitive backup functionality. Because the payloading is built in but relatively specific to the target workflow, the maturity is best categorized as OPERATIONAL.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A specific vulnerability identified as CVE-2026-49952 is referenced in what appears to be a CVE record creation or pull request entry, but no technical details about the flaw are provided in the content.
An authentication bypass vulnerability in Discuz! X5.0 that lets unauthenticated remote attackers obtain a valid signed token via an encryption oracle and access database backup and restore functionality, with possible arbitrary user impersonation via a race condition.
A critical authentication bypass / database exfiltration vulnerability in Discuz! X5.0 caused by cross-context cryptographic key reuse, allowing unauthenticated attackers to forge auth tokens for the database backup API and export the database; when chained with other flaws it can lead to full remote code execution.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.