Web Hack List

Preliminary research

Chaining Security Bugs in Discuz! X5.0: from Race Condition to Pre-Auth RCE

AI-collected research leads through 1 October 2026, including a bounded September review of selected social and community sources. Unranked, incomplete, not community-vetted, and subject to change.

The write-up chains cross-context token reuse, a database import race, automated CAPTCHA solving, and an administrative local-file-inclusion flaw into unauthenticated code execution against Discuz! X5.0. It documents the exploit mechanics, patch timeline, and three assigned CVEs.

Record

Published by
karmainsecurity.com
Topic
Server

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of karmainsecurity.com, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .