Exposure of Hidden Tags in Discourse Discussion Platform
CVE-2026-72732

4.3MEDIUM

Key Information:

Vendor

Discourse

Status
Vendor
CVE Published:
10 August 2026

What is CVE-2026-72732?

An issue in the Discourse discussion platform prior to versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0 allowed unauthorized users to access hidden tag names through the discourse_templates endpoint. The serializer in the affected versions failed to filter tags according to the request Guardian, ignoring tag group permissions. This oversight can lead to unintended data exposure, making it critical for users to update to the recommended versions to safeguard their discussions.

Affected Version(s)

discourse < 2026.1.6 < 2026.1.6

discourse >= 2026.5.0-latest, < 2026.5.2 < 2026.5.0-latest, 2026.5.2

discourse >= 2026.6.0-latest, < 2026.6.1 < 2026.6.0-latest, 2026.6.1

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.