Web Hack List

Preliminary research

Chaining Security Bugs in Discuz! X5.0: from Race Condition to Pre-Auth RCE

AI-collected research leads through 6 October 2026, including bounded month-by-month reviews of selected social and community sources from January through September. Unranked, incomplete, not community-vetted, and subject to change.

The write-up chains cross-context token reuse, a database import race, automated CAPTCHA solving, and an administrative local-file-inclusion flaw into unauthenticated code execution against Discuz! X5.0. It documents the exploit mechanics, patch timeline, and three assigned CVEs.

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of its author, first published at the original source. Preserved copies are kept so the citation survives its host.