Moderation Flaw in Discourse Discussion Platform by Discourse
CVE-2026-21865
What is CVE-2026-21865?
Discourse, an open source discussion platform, has a vulnerability that affects certain versions, allowing moderators to improperly convert private messages into public discussions. This flaw may expose sensitive communications to unauthorized users. It is crucial for site administrators to immediately upgrade to the patched versions or temporarily restrict the moderator role for untrusted users to maintain user privacy and forum integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
discourse < 3.5.4 < 3.5.4
discourse >= 2025.11.0-latest, < 2025.11.2 < 2025.11.0-latest, 2025.11.2
discourse >= 2025.12.0-latest, < 2025.12.1 < 2025.12.0-latest, 2025.12.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved