Open-source discussion platform Discourse Vulnerability Impacting Private Messages
CVE-2026-33424
What is CVE-2026-33424?
Discourse, an open-source discussion platform, has a vulnerability that allows an attacker to maintain access to a private message topic via invites even after they have lost their initial access. This issue affects versions released prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, which now have a security patch available. Due to the potential for unauthorized access to sensitive communication, it is essential that users update to the patched versions promptly. Currently, there are no known workarounds for this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
discourse >= 2026.1.0-latest, < 2026.1.2 < 2026.1.0-latest, 2026.1.2
discourse >= 2026.2.0-latest, < 2026.2.1 < 2026.2.0-latest, 2026.2.1
discourse = 2026.3.0-latest = 2026.3.0-latest