PT-2026-22188 · Discourse · Discourse

Davidtaylorhq

·

Published

2026-02-26

·

Updated

2026-03-03

·

CVE-2026-27162

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Discourse versions prior to 2025.12.2 Discourse versions prior to 2026.1.1 Discourse versions prior to 2026.2.0
Description Discourse, an open source discussion platform, had an issue where the posts nearby function was not properly filtering post types based on user permissions. Specifically, it was checking topic access but then returning all posts, including whispers that should only be visible to authorized users. To address this, it is recommended to use Post.secured(guardian) to properly filter post types based on user permissions.
Recommendations Update to Discourse version 2025.12.2 or later. Update to Discourse version 2026.1.1 or later. Update to Discourse version 2026.2.0 or later.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2026-27162
CVE-2026-27162
GHSA-GFFM-43J4-372W

Affected Products

Discourse