CVE-2026-44784 Details
Description
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, group owners who are not necessarily admins or moderators can view a group's outgoing email/SMTP credentials in plaintext via the group history log (/groups/:name/logs.json). Affected fields: email_password, email_username, smtp_server, smtp_port, smtp_ssl_mode. The most sensitive item is the SMTP password, which an owner could use to send mail as the group from outside Discourse. This impacts sites that have configured per-group SMTP credentials and granted group ownership to users who should not have access to those credentials. This issue has been patched in versions 2026.1.4, 2026.3.1, 2026.4.1, and 2026.5.0-latest.1.
A vulnerability exists in Discourse versions 2026.1.0-latest to prior to 2026.1.4, 2026.3.0-latest to prior to 2026.3.1, and 2026.4.0-latest to prior to 2026.4.1. Group owners, who are not necessarily admins or moderators, can access a group's outgoing email and SMTP credentials in plaintext through the group history log. The exposed fields include email_password, email_username, smtp_server, smtp_port, and smtp_ssl_mode. The SMTP password is particularly sensitive, as it allows an owner to send emails on behalf of the group from outside Discourse. This vulnerability affects sites with per-group SMTP credentials configured and where group ownership has been assigned to users who should not have access to this information.
To address this vulnerability, remove non-admin group owners from groups with configured email and SMTP credentials, or clear the email password on such groups and rotate it with the upstream mail provider. Users can update to Discourse versions 2026.1.4, 2026.3.1, 2026.4.1, or 2026.5.0-latest.1.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/discourse/discourse/security/advisories/GHSA-94c5-j24g-r99f | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| discourse discourse | < 2026.1.0 >= 2026.1.0, < 2026.1.4 >= 2026.3.0, < 2026.3.1 >= 2026.4.0, < 2026.4.1 2026.5.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 12, 2026 | New CVE Received | [email protected] |