CVE-2026-27491

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a type coercion issue in a post actions API endpoint allowed non-staff users to issue warnings to other users. Warnings are a staff-only moderation feature. The vulnerability required the attacker to be a logged-in user and to send a specifically crafted request. No data exposure or privilege escalation beyond the ability to create unauthorized user warnings was possible. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch. No known workarounds are available.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*
cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*
cpe:2.3:a:discourse:discourse:2026.3.0:*:*:*:latest:*:*:*

History

25 Mar 2026, 01:00

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3
CPE cpe:2.3:a:discourse:discourse:2026.3.0:*:*:*:latest:*:*:*
cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*
Summary
  • (es) Discourse es una plataforma de discusión de código abierto. Antes de las versiones 2026.3.0-latest.1, 2026.2.1 y 2026.1.2, un problema de coerción de tipos en un endpoint de la API de acciones de publicaciones permitía a usuarios que no eran parte del personal emitir advertencias a otros usuarios. Las advertencias son una característica de moderación solo para el personal. La vulnerabilidad requería que el atacante fuera un usuario con sesión iniciada y enviara una solicitud específicamente diseñada. No fue posible la exposición de datos ni la escalada de privilegios más allá de la capacidad de crear advertencias de usuario no autorizadas. Las versiones 2026.3.0-latest.1, 2026.2.1 y 2026.1.2 contienen un parche. No se conocen soluciones alternativas disponibles.
First Time Discourse
Discourse discourse
References () https://github.com/discourse/discourse/commit/60a588f4da4ab0feceb2c44787d4261b4f8757be - () https://github.com/discourse/discourse/commit/60a588f4da4ab0feceb2c44787d4261b4f8757be - Patch
References () https://github.com/discourse/discourse/commit/d3cb203feabc46d765ecb91f348613a2bd531b89 - () https://github.com/discourse/discourse/commit/d3cb203feabc46d765ecb91f348613a2bd531b89 - Patch
References () https://github.com/discourse/discourse/commit/f5fef73827da7520efc517357bd2a6bab35d7886 - () https://github.com/discourse/discourse/commit/f5fef73827da7520efc517357bd2a6bab35d7886 - Patch
References () https://github.com/discourse/discourse/security/advisories/GHSA-xq37-5fvf-4m4j - () https://github.com/discourse/discourse/security/advisories/GHSA-xq37-5fvf-4m4j - Vendor Advisory

19 Mar 2026, 21:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-19 21:17

Updated : 2026-03-25 01:00


NVD link : CVE-2026-27491

Mitre link : CVE-2026-27491

CVE.ORG link : CVE-2026-27491


JSON object : View

Products Affected

discourse

  • discourse
CWE
CWE-862

Missing Authorization