CVE-2026-49953 PUBLISHED

Discuz! X5.0 CAPTCHA Bypass via Predictable Character Set

Assigner: VulnCheck
Reserved: 02.06.2026 Published: 15.06.2026 Updated: 16.06.2026

Discuz! X5.0 releases 20260320 through 20260610 contains a CAPTCHA bypass vulnerability that allows unauthenticated remote attackers to defeat challenge controls by exploiting limited complexity and predictable character sets in generated CAPTCHA images. Attackers can train a custom optical character recognition model against collected CAPTCHA samples to reliably predict challenge text, bypassing protections on login, registration, and other functionality from automated abuse.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor Discuz!
Product Discuz! X5.0
Versions Default: unknown
  • affected from 20260320 to 20260610 (incl.)

Credits

  • Egidio Romano finder

References

Problem Types

  • Guessable CAPTCHA CWE