Open Source Discussion Platform Vulnerability in Discourse's Policy Plugin by Discourse
CVE-2026-26207
What is CVE-2026-26207?
The 'discourse-policy' plugin in Discourse enables authenticated users to manipulate policies on posts lacking appropriate permissions. This vulnerability arises from the 'PolicyController' failing to verify the current user's access rights, allowing unauthorized actions on posts in private categories. Users can also exploit the vulnerability to identify post IDs with associated policies by observing distinct error responses. The issue has been addressed in recent versions of Discourse by introducing access checks, reaffirming the significance of verifying post visibility before policy actions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
discourse < 2025.12.2 < 2025.12.2
discourse >= 2026.1.0-latest, < 2026.1.1 < 2026.1.0-latest, 2026.1.1
discourse >= 2026.2.0-latest, < 2026.2.0 < 2026.2.0-latest, 2026.2.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved