Impact
An authenticated user can request a preview of a hidden profile and receive the bio, location, and website fields that should remain private, exposing confidential user information. The weakness is an Information Disclosure flaw that bypasses the hide_profile setting designed to keep these fields hidden.
Affected Systems
Discourse, the open-source discussion platform, is affected for all releases prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2. These versions allow the hidden profile data to be retrieved through the user onebox preview feature.
Risk and Exploitability
The CVSS score is 4.3, indicating a medium level of severity. The EPSS score is below 1%, suggesting a low likelihood of widespread exploitation at the moment. The vulnerability is not listed in the CISA KEV catalog. Attackers need only an authenticated session on the platform and must have access to the user onebox feature, which is a remote action that can be performed over the web interface.
OpenCVE Enrichment