Description
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an authenticated user could eavesdrop on private AI bot conversations through the AI bot reply stream. The issue is fixed in 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.
Published: 2026-08-10
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authenticated user can intercept private AI bot conversations through the reply stream, exposing sensitive messages and compromising confidentiality. The flaw is a classic information disclosure vulnerability (CWE‑200) that does not affect integrity or availability.

Affected Systems

Discourse for versions before 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0. Users running these releases on any platform are susceptible.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires valid authenticated credentials and access to the AI bot feature, so the attack vector is likely an authenticated internal network context. There is no known public exploit at this time.

Generated by OpenCVE AI on August 10, 2026 at 18:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official patches by upgrading Discourse to version 2026.1.6, 2026.5.2, 2026.6.1, 2026.7.0, or a later release.
  • Restrict the AI bot feature to users with trusted roles by adjusting permissions or configuration settings.
  • Perform an audit of AI bot conversation logs to detect any unintended data exposure.

Generated by OpenCVE AI on August 10, 2026 at 18:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 10 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Description Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an authenticated user could eavesdrop on private AI bot conversations through the AI bot reply stream. The issue is fixed in 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.
Title Discourse: Unauthorized eavesdropping on private AI bot conversations.
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-10T16:57:12.320Z

Reserved: 2026-08-10T13:48:09.545Z

Link: CVE-2026-72726

cve-icon Vulnrichment

Updated: 2026-08-10T16:57:08.429Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T18:15:11Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor