Information Disclosure in Discourse Open-Source Discussion Platform
CVE-2026-55704
4.3MEDIUM
What is CVE-2026-55704?
The Discourse platform, prior to versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, allows users who have viewing permissions for a group's activity to access unpublished shared-draft content. This vulnerability could lead to the unintended disclosure of sensitive draft material, including titles and excerpt contents, via the group's posts and mentions endpoints. The issue has been resolved in the specified versions.
Affected Version(s)
discourse < 2026.1.6 < 2026.1.6
discourse >= 2026.5.0-latest, < 2026.5.2 < 2026.5.0-latest, 2026.5.2
discourse >= 2026.6.0-latest, < 2026.6.1 < 2026.6.0-latest, 2026.6.1