Impact
The vulnerability lies in serializes sensitive information—invited group names, sample invitees, and attendance statistics—to any user who can view the event topic, even if that user is not part of the private event invitee list. This misconfiguration allows unintended disclosure of who is invited to a private event and insights into attendance, constituting a privacy breach aligned with CWE‑200.
Affected Systems
Discourse installations running any release before 2026.6.0, 2026.5.1, 2026.4.2, or 2026.1.5 are affected. Administrators should verify whether their instance falls within these affected ranges and assess the risk of exposed event data.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity, and the EPSS score of < 1% suggests a very low exploitation probability; it is not listed in the CISA KEV catalog. The likely attack vector requires a user—authenticated or not—to have read access to a private event topic. Upon accessing the event, the harmless serialization process inadvertently exposes private invitee information. Because no additional conditions are required, any user with read access could exploit the flaw, but the overall risk remains low due to the limited scope and low exploit probability.
OpenCVE Enrichment