CVE-2025-69218
MEDIUMDiscourse < 3.5.4, < 2025.11.2, < 2025.12.1, < 2026.1.0 - Incorrect Authorization in Admin Report
Title source: llmDescription
Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, moderators can access the `top_uploads` admin report which should be restricted to admins only. This report displays direct URLs to all uploaded files on the site, including sensitive content such as user data exports, admin backups, and other private attachments that moderators should not have access to. This issue is patched in versions 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0. There is no workaround. Limit moderator privileges to trusted users until the patch is applied.
References (1)
Core 1
Core References
Third Party Advisory, Mitigation x_refsource_confirm
https://github.com/discourse/discourse/security/advisories/GHSA-79f9-j8h4-3w6w
Scores
CVSS v3
6.5
EPSS
0.0006
EPSS Percentile
17.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-863
Status
published
Products (3)
discourse/discourse
2025.12.0
discourse/discourse
2026.1.0
discourse/discourse
< 3.5.4
Published
Jan 28, 2026
Tracked Since
Feb 18, 2026