Open Source Discussion Platform Vulnerability in Discourse's Policy Plugin by Discourse
CVE-2026-26207

5.4MEDIUM

Key Information:

Vendor

Discourse

Status
Vendor
CVE Published:
26 February 2026

What is CVE-2026-26207?

The 'discourse-policy' plugin in Discourse enables authenticated users to manipulate policies on posts lacking appropriate permissions. This vulnerability arises from the 'PolicyController' failing to verify the current user's access rights, allowing unauthorized actions on posts in private categories. Users can also exploit the vulnerability to identify post IDs with associated policies by observing distinct error responses. The issue has been addressed in recent versions of Discourse by introducing access checks, reaffirming the significance of verifying post visibility before policy actions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

discourse < 2025.12.2 < 2025.12.2

discourse >= 2026.1.0-latest, < 2026.1.1 < 2026.1.0-latest, 2026.1.1

discourse >= 2026.2.0-latest, < 2026.2.0 < 2026.2.0-latest, 2026.2.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.