Access Control Flaw in Discourse Discuss Platform
CVE-2026-72724
4.3MEDIUM
What is CVE-2026-72724?
Discourse, an open-source discussion platform, has an access control vulnerability that affects versions before 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0. The vulnerability allows authenticated users to manipulate a public channel ID and access private message contents via the /onebox.json request. The flaw arises because the system resolves Chat::Thread using a thread_id without sufficient checks against channel_id, potentially exposing sensitive information. Users are recommended to upgrade to the latest versions to mitigate this risk.
Affected Version(s)
discourse < 2026.1.6 < 2026.1.6
discourse >= 2026.5.0-latest, < 2026.5.2 < 2026.5.0-latest, 2026.5.2
discourse >= 2026.6.0-latest, < 2026.6.1 < 2026.6.0-latest, 2026.6.1