PT-2026-22197 · Discourse · Discourse

34Selen

·

Published

2026-02-26

·

Updated

2026-03-03

·

CVE-2026-28227

CVSS v3.1

2.7

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Discourse versions prior to 2025.12.2 Discourse versions prior to 2026.1.1 Discourse versions prior to 2026.2.0
Description Discourse is an open source discussion platform. Trust Level 4 (TL4) users could publish topics into staff-only categories using the publish to category topic timer, bypassing intended authorization controls.
Recommendations Update to Discourse version 2025.12.2 or later. Update to Discourse version 2026.1.1 or later. Update to Discourse version 2026.2.0 or later.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2026-28227
CVE-2026-28227
GHSA-M49W-78MH-87JP

Affected Products

Discourse