IDOR Vulnerability in Discourse Directory Items Endpoint Affects User Privacy
CVE-2026-26265
What is CVE-2026-26265?
Discourse, a popular open-source discussion platform, has a vulnerability in its directory items endpoint that allows unauthorized access to private user field values. This IDOR issue enables any user, including those who are not logged in, to make requests for arbitrary user field IDs, thereby bypassing established visibility restrictions. As a result, sensitive information that should remain private, such as phone numbers and addresses, can be leaked in bulk. The vulnerability has been addressed in recent updates, which filter the user field IDs to ensure that non-staff users cannot access restricted data. Administrators are advised to update to the latest versions or take precautionary measures, such as modifying user fields to enhance data security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
discourse < 2025.12.2 < 2025.12.2
discourse >= 2026.1.0-latest, < 2026.1.1 < 2026.1.0-latest, 2026.1.1
discourse >= 2026.2.0-latest, < 2026.2.0 < 2026.2.0-latest, 2026.2.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved