Sensitive Information Exposure in Discourse by Open Source Community
CVE-2026-24742
What is CVE-2026-24742?
Discourse, a popular open-source discussion platform, has a vulnerability that allows non-admin moderators to access sensitive information in staff action logs. This exposure includes confidential data such as webhook payload URLs, API keys, site setting changes, private message content, and more, which are typically restricted to administrators. As a result, moderators have the potential to bypass established access controls, risking the extraction of sensitive data. An attacker leveraging leaked webhook secrets could impersonate integrated services, creating additional security concerns. This vulnerability has been addressed in the latest versions, and administrators are advised to ensure that only fully trusted users are appointed as moderators.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
discourse < 3.5.4 < 3.5.4
discourse >= 2025.11.0-latest, < 2025.11.2 < 2025.11.0-latest, 2025.11.2
discourse >= 2025.12.0-latest, < 2025.12.1 < 2025.12.0-latest, 2025.12.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved