Channel Membership Inference in Discourse Discussion Platform
CVE-2026-32618
4.3MEDIUM
What is CVE-2026-32618?
Discourse, an open-source discussion platform, has a vulnerability that can potentially allow unauthorized users to infer channel memberships through chat user searches. This issue affects specific versions of the platform and has been addressed in later releases, specifically versions 2026.1.3, 2026.2.2, and 2026.3.0. Users are strongly encouraged to update their installations to safeguard against this risk.
Affected Version(s)
discourse >= 2026.1.0-latest, < 2026.1.3 < 2026.1.0-latest, 2026.1.3
discourse >= 2026.2.0-latest, < 2026.2.2 < 2026.2.0-latest, 2026.2.2
discourse >= 2026.3.0-latest, < 2026.3.0 < 2026.3.0-latest, 2026.3.0