CVE-2026-84302 Details
Description
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, Discourse AI reviewables associated with private messages could appear in the moderator review queue of a moderator who was not a participant in the message. Reviewable visibility filtering did not restrict private-message reviewables to the audience permitted to access the underlying private-message topic, allowing the moderator to read otherwise confidential content. Depending on the available reviewable action, the moderator could also modify the private message by closing its topic or deleting a post. Exploitation requires an authenticated moderator account and a pre-existing Discourse AI reviewable associated with a private message. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.
A vulnerability in Discourse's handling of AI-generated reviewables can lead to unauthorized access to private message content by non-participant moderators. This issue affects Discourse versions prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0. The vulnerability arises because the reviewable visibility filtering does not properly restrict access to private messages, allowing moderators to read confidential content. Exploitation requires an authenticated moderator account and a pre-existing Discourse AI reviewable linked to a private message.
Users can upgrade to Discourse versions 2026.1.6, 2026.5.2, 2026.6.1, or 2026.7.0 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 24, 2026CISA-ADP
Assessed Sep 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Discourse | >= 2026.1.0-latest (semver) >= 2026.5.0-latest (semver) >= 2026.6.0-latest (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 24, 2026 | CVE Modified | CISA-ADP |
| Sep 24, 2026 | New CVE Received | [email protected] |
Volerion