Vulnerability in Discourse Discussion Platform Allows Unauthorized Group Privileges
CVE-2026-44787

8.2HIGH

Key Information:

Vendor

Discourse

Status
Vendor
CVE Published:
9 July 2026

What is CVE-2026-44787?

CVE-2026-44787 is a vulnerability identified in the Discourse discussion platform, an open-source tool designed for creating and managing online forums and discussions. This vulnerability relates to the user registration and group assignment process, specifically allowing newly registered users to manipulate the primary_group_id parameter. In instances where the configuration allows certain groups to participate in private discussions (whispers), this vulnerability enables unauthorized users to gain unexpected access and privileges, effectively circumventing the intended membership restrictions. Such exploitation can lead to significant breaches of privacy and trust on platforms that utilize Discourse for community engagement, potentially giving malicious users the ability to view or participate in sensitive discussions without proper authorization.

Potential impact of CVE-2026-44787

  1. Unauthorized Access to Sensitive Information: The vulnerability may allow unauthorized users to access private discussions and sensitive conversations that were meant to be restricted to specific groups, threatening the confidentiality of communications within the platform.

  2. Erosion of Trust in the Platform: Instances of unauthorized users exploiting this flaw can undermine user trust in the Discourse platform, potentially resulting in user attrition and a damaged reputation for organizations that rely on Discourse for hosting community discussions.

  3. Facilitation of Malicious Activities: By gaining unauthorized group privileges, attackers could exploit this vulnerability to spread misinformation, conduct harassment, or engage in other harmful activities that impact the overall integrity of community interactions on affected forums.

Affected Version(s)

discourse >= 2026.1.0-latest, < 2026.1.5 < 2026.1.0-latest, 2026.1.5

discourse >= 2026.4.0-latest, < 2026.4.2 < 2026.4.0-latest, 2026.4.2

discourse >= 2026.5.0-latest, < 2026.5.1 < 2026.5.0-latest, 2026.5.1

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.