PT-2026-29319 · Discourse · Discourse

Davidtaylorhq

·

Published

2026-03-31

·

Updated

2026-04-07

·

CVE-2026-33415

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Discourse versions 2026.1.0 through 2026.1.2, 2026.2.0 through 2026.2.1, and 2026.3.0 through 2026.3.0
Description Discourse, an open-source discussion platform, had insufficient access controls on a sentiment analytics endpoint. This allowed an authenticated moderator-level user to bypass category permission boundaries and retrieve post content, topic titles, and usernames from categories they were not authorized to view.
Recommendations Update to Discourse version 2026.1.3 or later. Update to Discourse version 2026.2.2 or later. Update to Discourse version 2026.3.0 or later.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2026-33415
CVE-2026-33415
GHSA-VJ5F-GG8M-93XG

Affected Products

Discourse