PT-2026-26541 · Discourse · Discourse
Jomaxro
·
Published
2026-03-20
·
Updated
2026-03-27
·
CVE-2026-30891
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Discourse versions prior to 2026.3.0-latest.1
Discourse versions prior to 2026.2.1
Discourse versions prior to 2026.1.2
Description
Discourse is an open-source discussion platform. Insufficient authorization checks in the
user actions API endpoint allowed a user to access another user's private activity. The user actions endpoint is vulnerable, potentially exposing private user data. The vulnerable parameter is not specified.Recommendations
Update Discourse to version 2026.3.0-latest.1 or later.
Update Discourse to version 2026.2.1 or later.
Update Discourse to version 2026.1.2 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Discourse