PT-2026-22185 · Discourse · Discourse

Davidtaylorhq

·

Published

2026-02-26

·

Updated

2026-03-03

·

CVE-2026-27150

CVSS v3.1

3.8

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Discourse versions prior to 2025.12.2 Discourse versions prior to 2026.1.1 Discourse versions prior to 2026.2.0
Description A missing validate before create authorization check in the Data Explorer's QueryGroupBookmarkable component allows any authenticated user to create bookmarks for query groups they are not authorized to access. This can lead to the disclosure of metadata through bookmark reminder notifications.
Recommendations Update to Discourse version 2025.12.2 or later. Update to Discourse version 2026.1.1 or later. Update to Discourse version 2026.2.0 or later.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2026-27150
CVE-2026-27150
GHSA-RW95-54QR-QRW8

Affected Products

Discourse