CVE-2026-26077 Details
Description
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, several webhook endpoints (SendGrid, Mailjet, Mandrill, Postmark, SparkPost) in the `WebhooksController` accepted requests without a valid authentication token when no token was configured. This allowed unauthenticated attackers to forge webhook payloads and artificially inflate user bounce scores, potentially causing legitimate user emails to be disabled. The Mailpace endpoint had no token validation at all. Starting in versions 2025.12.2, 2026.1.1, and 2026.2.0, all webhook endpoints reject requests with a 406 response when no authentication token is configured. As a workaround, ensure that webhook authentication tokens are configured for all email provider integrations in site settings (e.g., `sendgrid_verification_key`, `mailjet_webhook_token`, `postmark_webhook_token`, `sparkpost_webhook_token`). There's no current workaround for mailpace before getting this fix.
A vulnerability exists in Discourse webhook endpoints for SendGrid, Mailjet, Mandrill, Postmark, and SparkPost, prior to versions 2025.12.2, 2026.1.1, and 2026.2.0. These endpoints accepted requests without a valid authentication token when none was configured, allowing unauthenticated attackers to forge webhook payloads and artificially inflate user bounce scores, which could lead to the disabling of legitimate user emails. The Mailpace endpoint lacked any token validation. In the patched versions, all webhook endpoints now require an authentication token and will reject requests without one, responding with a 406 status. As a workaround, users can configure webhook authentication tokens for their email provider integrations, except for Mailpace, which currently has no workaround available.
Users should ensure that webhook authentication tokens are configured for all email provider integrations in the site settings. For the Mailpace endpoint, wait for the upcoming fix.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/discourse/discourse/security/advisories/GHSA-j67c-53j2-4hfw | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| discourse discourse | < 2025.12.0 >= 2026.1.0, < 2026.1.1 2026.2.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 2, 2026 | Initial Analysis | [email protected] |
| Feb 26, 2026 | New CVE Received | [email protected] |