CVE-2026-49256 Details
Description
Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, restricted tag and tag-group names attached to publicly readable categories as allowed_tags, allowed_tag_groups, or required tag groups could leak to anonymous and unauthorized users through category and group endpoints. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5.
A vulnerability in Discourse prior to versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5 allows restricted tag and tag-group names to leak to anonymous and unauthorized users. This occurs when such tags are attached to publicly readable categories and the category endpoints are accessed. The issue arises from the improper handling of tag group restrictions, which can expose sensitive tagging information through various category and group endpoints.
Users can upgrade to Discourse versions 2026.6.0, 2026.5.1, 2026.4.2, or 2026.1.5 to address this vulnerability. If an immediate upgrade is not possible, the restricted tag and tag-group references can be removed from any publicly readable category as a temporary workaround.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/discourse/discourse/releases/tag/v2026.1.5 | [email protected] | Release NotesPatch |
| https://github.com/discourse/discourse/releases/tag/v2026.4.2 | [email protected] | Release Notes |
| https://github.com/discourse/discourse/releases/tag/v2026.5.1 | [email protected] | Release Notes |
| https://github.com/discourse/discourse/releases/tag/v2026.6.0 | [email protected] | Release Notes |
| https://github.com/discourse/discourse/security/advisories/GHSA-mwp7-572g-6qpx | [email protected] | Vendor AdvisoryMitigation |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| discourse discourse | >= 2026.1.0, < 2026.1.5 >= 2026.4.0, < 2026.4.2 >= 2026.5.0, < 2026.5.1 2026.6.0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | Initial Analysis | [email protected] |
| Jul 10, 2026 | CVE Modified | CISA-ADP |
| Jul 9, 2026 | New CVE Received | [email protected] |