Eavesdropping Vulnerability in Discourse Discussion Platform
CVE-2026-72726
6.5MEDIUM
What is CVE-2026-72726?
In the Discourse platform, prior to specified versions, an authenticated user could leverage a vulnerability to eavesdrop on private conversations held by AI bots via the reply stream. This issue has since been remediated in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, enhancing the platform's security against unauthorized data exposure.
Affected Version(s)
discourse < 2026.1.6 < 2026.1.6
discourse >= 2026.5.0, < 2026.5.2 < 2026.5.0, 2026.5.2
discourse >= 2026.6.0, < 2026.6.1 < 2026.6.0, 2026.6.1