Impact
The vulnerability stems from a flaw in Discourse’s handling of tag routes. Users who lack authentication or proper authorization can request hidden tags meant to be visible only to staff, causing confidential tags and their linked data to be inadvertently exposed.
Affected Systems
Discourse instances that enable tagging and configure staff‑only tag groups are subject to this issue. It affects software versions 2026.1.0 through just before 2026.1.3, 2026.2.0 through just before 2026.2.2, and 2026.3.0 through just before 2026.3.0.
Risk and Exploitability
The CVSS score of 6.3 indicates medium severity. Because the vulnerability can be triggered by unauthenticated access, an attacker can expose confidential staff‑only tag data by simply requesting the hidden tag URL. The EPSS score of < 1% signifies a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack path requires no special privileges beyond access to the public instance.
OpenCVE Enrichment