Sensitive Information Exposure in Discourse by Open Source Community
CVE-2026-24742

6.5MEDIUM

Key Information:

Vendor

Discourse

Status
Vendor
CVE Published:
28 January 2026

What is CVE-2026-24742?

Discourse, a popular open-source discussion platform, has a vulnerability that allows non-admin moderators to access sensitive information in staff action logs. This exposure includes confidential data such as webhook payload URLs, API keys, site setting changes, private message content, and more, which are typically restricted to administrators. As a result, moderators have the potential to bypass established access controls, risking the extraction of sensitive data. An attacker leveraging leaked webhook secrets could impersonate integrated services, creating additional security concerns. This vulnerability has been addressed in the latest versions, and administrators are advised to ensure that only fully trusted users are appointed as moderators.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

discourse < 3.5.4 < 3.5.4

discourse >= 2025.11.0-latest, < 2025.11.2 < 2025.11.0-latest, 2025.11.2

discourse >= 2025.12.0-latest, < 2025.12.1 < 2025.12.0-latest, 2025.12.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.