Preliminary research
Chaining Security Bugs in Discuz! X5.0: from Race Condition to Pre-Auth RCE
AI-collected research leads through 1 October 2026, including a bounded September review of selected social and community sources. Unranked, incomplete, not community-vetted, and subject to change.
The write-up chains cross-context token reuse, a database import race, automated CAPTCHA solving, and an administrative local-file-inclusion flaw into unauthenticated code execution against Discuz! X5.0. It documents the exploit mechanics, patch timeline, and three assigned CVEs.
Record
- Published by
- karmainsecurity.com
- Topic
- Server
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of karmainsecurity.com, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .