We found results for “”
CVE-2026-21865
Good to know:
Date: January 28, 2026
Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, moderators can convert some personal messages to public topics when they shouldn't have access. This issue is patched in versions 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0. As a workaround, site admin can temporarily revoke the moderation role from untrusted moderators or remove the moderator group from the "personal message enabled groups" site setting until the Discourse instance has been upgraded to a version that has been patched.
Severity Score
Severity Score
Weakness Type (CWE)
Missing Authorization
CWE-862Top Fix
Upgrade Version
Upgrade to version https://github.com/discourse/discourse.git - v2026.1.0;https://github.com/discourse/discourse.git - v2025.11.2;https://github.com/discourse/discourse.git - v3.5.4;https://github.com/discourse/discourse.git - v2025.12.1
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | HIGH |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | HIGH |
| Integrity (I): | HIGH |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


