Impact
An authorization bypass in Discourse’s Category Chatables Controller allows moderators to retrieve hidden group names and user counts via the /category-chatables endpoint. This flaw results in a confidentiality breach by leaking sensitive group membership information and size metadata, exposing organizational data to any user with moderator privileges.
Affected Systems
The vulnerability affects Discourse releases 2026.1.0 through the build that precedes 2026.1.3, 2026.2.0 through the build that precedes 2026.2.2, and 2026.3.0 builds before 2026.3.0. Versions 2026.1.3, 2026.2.2, and 2026.3.0 or later contain the fix.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation. This vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Attackers would need legitimate moderator access and the ability to invoke the exposed API; there is no risk of remote code execution. The impact is primarily on data confidentiality for hidden groups.
OpenCVE Enrichment