Data Exposure Vulnerability in Discourse Discussion Platform
CVE-2026-32244
5.3MEDIUM
What is CVE-2026-32244?
An issue in Discourse allows outdated cached AI summaries to reveal previously removed content to anonymous and unprivileged users. This vulnerability affects versions prior to 2026.1.4, 2026.3.1, 2026.4.1, and 2026.5.0-latest. Users cannot regenerate summaries, making it possible for sensitive information to be unintentionally exposed. The problem can be mitigated by tightening group permissions for summary generation within summarization Personas.
Affected Version(s)
discourse < 2026.1.4 < 2026.1.4
discourse >= 2026.3.0-latest, < 2026.3.1 < 2026.3.0-latest, 2026.3.1
discourse >= 2026.4.0-latest, < 2026.4.1 < 2026.4.0-latest, 2026.4.1