PT-2026-22197 · Discourse · Discourse

34Selen

·

Publicado

2026-02-26

·

Atualizado

2026-03-03

·

CVE-2026-28227

CVSS v3.1

2.7

Baixa

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Discourse versions prior to 2025.12.2 Discourse versions prior to 2026.1.1 Discourse versions prior to 2026.2.0
Description Discourse is an open source discussion platform. Trust Level 4 (TL4) users could publish topics into staff-only categories using the publish to category topic timer, bypassing intended authorization controls.
Recommendations Update to Discourse version 2025.12.2 or later. Update to Discourse version 2026.1.1 or later. Update to Discourse version 2026.2.0 or later.

Exploit

Correção

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BIT-DISCOURSE-2026-28227
CVE-2026-28227
GHSA-M49W-78MH-87JP

Produtos afetados

Discourse