Vulnerability in Discourse Discussion Platform Allows Unauthorized Group Privileges
CVE-2026-44787
What is CVE-2026-44787?
CVE-2026-44787 is a vulnerability identified in the Discourse discussion platform, an open-source tool designed for creating and managing online forums and discussions. This vulnerability relates to the user registration and group assignment process, specifically allowing newly registered users to manipulate the primary_group_id parameter. In instances where the configuration allows certain groups to participate in private discussions (whispers), this vulnerability enables unauthorized users to gain unexpected access and privileges, effectively circumventing the intended membership restrictions. Such exploitation can lead to significant breaches of privacy and trust on platforms that utilize Discourse for community engagement, potentially giving malicious users the ability to view or participate in sensitive discussions without proper authorization.
Potential impact of CVE-2026-44787
-
Unauthorized Access to Sensitive Information: The vulnerability may allow unauthorized users to access private discussions and sensitive conversations that were meant to be restricted to specific groups, threatening the confidentiality of communications within the platform.
-
Erosion of Trust in the Platform: Instances of unauthorized users exploiting this flaw can undermine user trust in the Discourse platform, potentially resulting in user attrition and a damaged reputation for organizations that rely on Discourse for hosting community discussions.
-
Facilitation of Malicious Activities: By gaining unauthorized group privileges, attackers could exploit this vulnerability to spread misinformation, conduct harassment, or engage in other harmful activities that impact the overall integrity of community interactions on affected forums.
Affected Version(s)
discourse >= 2026.1.0-latest, < 2026.1.5 < 2026.1.0-latest, 2026.1.5
discourse >= 2026.4.0-latest, < 2026.4.2 < 2026.4.0-latest, 2026.4.2
discourse >= 2026.5.0-latest, < 2026.5.1 < 2026.5.0-latest, 2026.5.1