2026 NationStates — production-server RCE; emails, MD5 hashes, IPs, and possible private messages copied
Data compromised
Email addresses, MD5 password hashes, IP addresses, browser user-agent strings, and possibly internal telegram/private-message content
Technical writeup
NationStates confirmed that a player reporting a vulnerability exceeded authorized testing boundaries and achieved remote code execution on the production server around January 27, 2026. The attacker copied application code and user data, forcing the game offline while the operator rebuilt infrastructure. The bug chain involved insufficient sanitization in a Dispatch Search feature and a double-parsing issue. Exposed data included current and historical account emails, MD5 password hashes, login IP addresses, browser user-agent strings, and likely some internal telegram/private-message content; the service stated it did not collect real names, physical addresses, phone numbers, or credit cards.
Root cause
Application vulnerability enabling RCE on production server after unsafe vulnerability testing