Information Disclosure in Discourse Open-Source Discussion Platform
CVE-2026-55704

4.3MEDIUM

Key Information:

Vendor

Discourse

Status
Vendor
CVE Published:
17 August 2026

What is CVE-2026-55704?

The Discourse platform, prior to versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, allows users who have viewing permissions for a group's activity to access unpublished shared-draft content. This vulnerability could lead to the unintended disclosure of sensitive draft material, including titles and excerpt contents, via the group's posts and mentions endpoints. The issue has been resolved in the specified versions.

Affected Version(s)

discourse < 2026.1.6 < 2026.1.6

discourse >= 2026.5.0-latest, < 2026.5.2 < 2026.5.0-latest, 2026.5.2

discourse >= 2026.6.0-latest, < 2026.6.1 < 2026.6.0-latest, 2026.6.1

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.