PT-2026-26423 · Discourse · Discourse

Davidtaylorhq

·

Published

2026-03-19

·

Updated

2026-03-27

·

CVE-2026-32099

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Discourse versions prior to 2026.3.0-latest.1 Discourse versions prior to 2026.2.1 Discourse versions prior to 2026.1.2
Description Discourse is an open-source discussion platform. When a user has hide profile enabled, their bio, location, and website were still exposed through the user onebox preview. An authenticated user could request a onebox for a hidden user's profile URL and receive their hidden profile fields (bio, location, website) in the response.
Recommendations Update to Discourse version 2026.3.0-latest.1 or later. Update to Discourse version 2026.2.1 or later. Update to Discourse version 2026.1.2 or later.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2026-32099
CVE-2026-32099
GHSA-Q83G-CJ26-J4X5

Affected Products

Discourse