Privacy Vulnerability in Discourse Open-Source Discussion Platform
CVE-2026-84302
What is CVE-2026-84302?
A vulnerability in the Discourse platform allowed private message AI reviewables to be visible in the moderator review queue, even to moderators not involved in those private conversations. This oversight in visibility filtering permitted unauthorized access to confidential information, enabling malicious actors with moderator privileges to read and potentially alter private messages by closing topics or deleting posts. The vulnerability requires an authenticated moderator account and is addressed in subsequent updates, namely versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.
Affected Version(s)
discourse < 2026.7.0 < 2026.7.0
discourse >= 2026.6.0-latest, < 2026.6.1 < 2026.6.0-latest, 2026.6.1
discourse >= 2026.5.0-latest, < 2026.5.2 < 2026.5.0-latest, 2026.5.2