CVE-2026-32615

MEDIUM

Discourse: Category group moderators can perform actions on topics in restricted categories without read access

Title source: cna

Description

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, category group moderators could perform privileged actions on topics inside private categories they did not have read access to. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.

Scores

CVSS v3 5.4
EPSS 0.0003
EPSS Percentile 8.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-285
Status published
Products (5)
discourse/discourse 2026.3.0 (2 CPE variants)
discourse/discourse 2026.1.0 - 2026.1.3
discourse/discourse >= 2026.1.0-latest, < 2026.1.3
discourse/discourse >= 2026.2.0-latest, < 2026.2.2
discourse/discourse >= 2026.3.0-latest, < 2026.3.0
Published Mar 31, 2026
Tracked Since Mar 31, 2026