Description
Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, moderators can convert some personal messages to public topics when they shouldn't have access. This issue is patched in versions 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0. As a workaround, site admin can temporarily revoke the moderation role from untrusted moderators or remove the moderator group from the "personal message enabled groups" site setting until the Discourse instance has been upgraded to a version that has been patched.
Published: 2026-01-28
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized content publication through improper authorization
Action: Apply Patch
AI Analysis

Impact

In Discourse versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, moderators can convert personal messages into public topics even when they lack the necessary permission. This flaw allows a moderator to publish private or sensitive information to all users, violating confidentiality and potentially compromising the platform’s integrity by broadcasting content that should remain restricted. The vulnerability is grounded in a missing authorization check (CWE‑862).

Affected Systems

The affected platform is Discourse, an open‑source discussion community software. Attack surfaces include any installation running a pre‑patched release of the product. Versions explicitly mentioned as vulnerable are those older than 3.5.4 and the 2025.x and 2026.1.0 releases listed in the advisory. Installing the latest stable releases fixes the issue.

Risk and Exploitability

The CVSS score of 6.5 indicates medium severity, reflecting a moderate impact on confidentiality and integrity without direct denial of service. The EPSS score of less than 1% shows that exploitation is considered unlikely in the wild at this time, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an internal moderator account; an attacker with moderator privileges can directly transform a private conversation into a public topic, enabling disclosure of sensitive information. The absence of a public exploit and the low EPSS suggest that current risk is moderate but potentially higher in environments with untrusted moderators. Maintaining updated versions and restricting moderator roles are essential mitigations.

Generated by OpenCVE AI on April 18, 2026 at 01:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Discourse installation to version 3.5.4 or later, 2025.11.2 or later, 2025.12.1 or later, or 2026.1.0 or later, whichever is applicable to the deployment.
  • If an upgrade is not immediately possible, remove the moderator group from the "personal message enabled groups" site setting to prevent moderators from converting personal messages to public topics.
  • If untrusted moderators must retain some moderation capabilities, temporarily revoke the moderation role from those users until the instance is upgraded to a patched release.

Generated by OpenCVE AI on April 18, 2026 at 01:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 30 Jan 2026 20:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:discourse:discourse:*:*:*:*:stable:*:*:*
cpe:2.3:a:discourse:discourse:2025.12.0:*:*:*:stable:*:*:*
cpe:2.3:a:discourse:discourse:2026.1.0:*:*:*:stable:*:*:*

Thu, 29 Jan 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Discourse
Discourse discourse
Vendors & Products Discourse
Discourse discourse

Wed, 28 Jan 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 28 Jan 2026 20:00:00 +0000

Type Values Removed Values Added
Description Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, moderators can convert some personal messages to public topics when they shouldn't have access. This issue is patched in versions 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0. As a workaround, site admin can temporarily revoke the moderation role from untrusted moderators or remove the moderator group from the "personal message enabled groups" site setting until the Discourse instance has been upgraded to a version that has been patched.
Title Discourse topic conversion permission vulnerability for moderators
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Discourse Discourse
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-01-28T20:10:06.915Z

Reserved: 2026-01-05T16:44:16.368Z

Link: CVE-2026-21865

cve-icon Vulnrichment

Updated: 2026-01-28T20:09:49.084Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-28T20:16:14.530

Modified: 2026-01-30T20:30:18.947

Link: CVE-2026-21865

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T01:45:33Z

Weaknesses