Unauthorized Modification of User Group Notifications in Discourse by Discourse
CVE-2026-33423
1.3LOW
What is CVE-2026-33423?
A vulnerability in the Discourse discussion platform allows staff members to modify the group notification levels of any user, potentially altering their preferences without consent. This issue is present in versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, and those utilizing these versions are advised to upgrade promptly, as no workarounds exist.
Affected Version(s)
discourse >= 2026.1.0-latest, < 2026.1.2 < 2026.1.0-latest, 2026.1.2
discourse >= 2026.2.0-latest, < 2026.2.1 < 2026.2.0-latest, 2026.2.1
discourse = 2026.3.0-latest = 2026.3.0-latest