Description
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.1, on sites with category group moderation enabled, the review queue could include an excerpt (and permalink) of the private message attached to a flag, even when the reviewing category moderator was not a participant in that message. These notify_moderators flag messages are addressed only to moderators and, for core flags, to a category's moderation groups as they existed when the flag was raised, so a category group moderator could read flag-discussion content they were not authorized to see. This affects official plugins that create such messages and core flags raised before a moderator's group was granted moderation of the category. Only the confidentiality of a limited excerpt of these flag-related private messages is affected; no content can be modified or deleted. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.1.
Published: 2026-08-17
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A bug in the review queue caused a short excerpt and a permalink of private messages attached to flag notifications to be shown to moderators of a category group that had no role in the original private message. The admission of this data exposed a limited portion of the flag‑related private message content, however the vulnerability did not allow any modification or deletion of the messages. The principal effect is a breach of confidentiality for that excerpted data.

Affected Systems

The vulnerability affects the Discourse open‑source discussion platform. Sites running Discourse versions earlier than 2026.1.6, 2026.5.2, 2026.6.1 or 2026.7.1 and that have category group moderation enabled can be impacted. No other vendors or products are listed as affected.

Risk and Exploitability

The CVSS score of 4.3 places the vulnerability in the moderate range; the EPSS score is not available and the issue is not listed in the CISA KEV catalog, indicating it is not known to be exploited in the wild. The likely attack vector is an authenticated moderator belonging to a category’s moderation group, who can view the review queue. Because the vulnerability only reveals a snippet of a private message and cannot alter any data, the risk is confined to confidentiality of that excerpt. Nonetheless, any user with appropriate moderator permissions could gain unintended visibility into private communication.

Generated by OpenCVE AI on August 17, 2026 at 16:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Discourse installation to version 2026.1.6 or later (2026.5.2, 2026.6.1, or 2026.7.1 are all patched).
  • If the site does not require category group moderation, disable that feature to prevent the review queue from displaying flag‑related private message excerpts.
  • Audit existing flagged messages for sensitive content and consider removing or deleting the flag notification to eliminate exposed excerpts, as the bug cannot be exploited to alter the underlying messages.

Generated by OpenCVE AI on August 17, 2026 at 16:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Discourse
Discourse discourse
Vendors & Products Discourse
Discourse discourse

Mon, 17 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Description Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.1, on sites with category group moderation enabled, the review queue could include an excerpt (and permalink) of the private message attached to a flag, even when the reviewing category moderator was not a participant in that message. These notify_moderators flag messages are addressed only to moderators and, for core flags, to a category's moderation groups as they existed when the flag was raised, so a category group moderator could read flag-discussion content they were not authorized to see. This affects official plugins that create such messages and core flags raised before a moderator's group was granted moderation of the category. Only the confidentiality of a limited excerpt of these flag-related private messages is affected; no content can be modified or deleted. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.1.
Title Discourse: Review queue exposes flag-related private message excerpts to category group moderators
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Discourse Discourse
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-17T19:00:49.059Z

Reserved: 2026-07-07T15:00:50.979Z

Link: CVE-2026-59829

cve-icon Vulnrichment

Updated: 2026-08-17T19:00:44.231Z

cve-icon NVD

Status : Received

Published: 2026-08-17T16:17:01.687

Modified: 2026-08-17T19:16:32.087

Link: CVE-2026-59829

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T16:30:06Z

Weaknesses