PT-2026-26427 · Discourse · Discourse

Davidtaylorhq

·

Published

2026-03-19

·

Updated

2026-03-27

·

CVE-2026-33410

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Discourse versions prior to 2026.3.0-latest.1 Discourse versions prior to 2026.2.1 Discourse versions prior to 2026.1.2
Description Discourse, an open-source discussion platform, has authorization issues within its chat direct message API. Specifically, the target groups parameter, when used for creating or modifying direct message channels, was not properly validated to ensure the acting user had visibility into the specified groups. This allowed an authenticated user to potentially access information about members of private or hidden groups by crafting a specific API request. Additionally, the can chat? function only verified group membership and did not consider the chat enabled user preference, enabling chat-disabled users to create or query direct message channels and potentially view private last message content. The API endpoints involved are those used for creating and managing direct message channels. The vulnerable parameter is target groups.
Recommendations Update Discourse to version 2026.3.0-latest.1 or later. Update Discourse to version 2026.2.1 or later. Update Discourse to version 2026.1.2 or later.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2026-33410
CVE-2026-33410
GHSA-2M5J-6V2R-CQ2H

Affected Products

Discourse