CVE-2026-27150

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, missing `validate_before_create` authorization in Data Explorer's `QueryGroupBookmarkable` allows any logged-in user to create bookmarks for query groups they don't have access to, enabling metadata disclosure via bookmark reminder notifications. Versions 2025.12.2, 2026.1.1, and 2026.2.0 fix this issue and also make sure `validate_before_create` throws NotImplementedError in BaseBookmarkable if not implemented, to prevent similar issues in the future. No known workarounds are available.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*
cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*
cpe:2.3:a:discourse:discourse:2026.2.0:*:*:*:latest:*:*:*

History

02 Mar 2026, 18:22

Type Values Removed Values Added
CPE cpe:2.3:a:discourse:discourse:2026.2.0:*:*:*:latest:*:*:*

02 Mar 2026, 17:44

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 3.8
CPE cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*
References () https://github.com/discourse/discourse/security/advisories/GHSA-rw95-54qr-qrw8 - () https://github.com/discourse/discourse/security/advisories/GHSA-rw95-54qr-qrw8 - Vendor Advisory
First Time Discourse
Discourse discourse

27 Feb 2026, 14:06

Type Values Removed Values Added
Summary
  • (es) Discourse es una plataforma de discusión de código abierto. Antes de las versiones 2025.12.2, 2026.1.1 y 2026.2.0, la falta de autorización 'validate_before_create' en 'QueryGroupBookmarkable' de Data Explorer permite a cualquier usuario autenticado crear marcadores para grupos de consultas a los que no tienen acceso, lo que permite la divulgación de metadatos a través de notificaciones de recordatorio de marcadores. Las versiones 2025.12.2, 2026.1.1 y 2026.2.0 solucionan este problema y también aseguran que 'validate_before_create' arroje un NotImplementedError en BaseBookmarkable si no se implementa, para prevenir problemas similares en el futuro. No se conocen soluciones alternativas disponibles.

26 Feb 2026, 21:28

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-26 21:28

Updated : 2026-03-02 18:22


NVD link : CVE-2026-27150

Mitre link : CVE-2026-27150

CVE.ORG link : CVE-2026-27150


JSON object : View

Products Affected

discourse

  • discourse
CWE
CWE-862

Missing Authorization