Access Control Flaw in Discourse by Discourse
CVE-2025-68933
What is CVE-2025-68933?
A vulnerability exists in Discourse that allows non-admin moderators to change post ownership in restricted categories and private messages despite lacking access. If configured with the moderators_change_post_ownership permission enabled, these moderators can export sensitive data from posts they shouldn't access. The vulnerability has been addressed in updated versions with stricter visibility checks implemented. Administrators are advised to upgrade to the patched versions or disable the ownership transfer setting to mitigate potential risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
discourse < 3.5.4 < 3.5.4
discourse >= 2025.11.0-latest, < 2025.11.2 < 2025.11.0-latest, 2025.11.2
discourse >= 2025.12.0-latest, < 2025.12.1 < 2025.12.0-latest, 2025.12.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved