← NationStates

2026 NationStates — production-server RCE; emails, MD5 hashes, IPs, and possible private messages copied

2026 Unknown records affected Share on X

Data compromised

Email addresses, MD5 password hashes, IP addresses, browser user-agent strings, and possibly internal telegram/private-message content

Technical writeup

NationStates confirmed that a player reporting a vulnerability exceeded authorized testing boundaries and achieved remote code execution on the production server around January 27, 2026. The attacker copied application code and user data, forcing the game offline while the operator rebuilt infrastructure. The bug chain involved insufficient sanitization in a Dispatch Search feature and a double-parsing issue. Exposed data included current and historical account emails, MD5 password hashes, login IP addresses, browser user-agent strings, and likely some internal telegram/private-message content; the service stated it did not collect real names, physical addresses, phone numbers, or credit cards.

Root cause

Application vulnerability enabling RCE on production server after unsafe vulnerability testing

References