CVE-2026-29072

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, users who do not belong to the allowed policy creation groups can create functional policy acceptance widgets in posts under the right conditions. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch. As a workaround, disable the discourse-policy plugin by disabling the `policy_enabled` site setting.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*
cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*
cpe:2.3:a:discourse:discourse:2026.3.0:*:*:*:latest:*:*:*

History

23 Mar 2026, 20:11

Type Values Removed Values Added
Summary
  • (es) Discourse es una plataforma de discusión de código abierto. Anteriormente a las versiones 2026.3.0-latest.1, 2026.2.1 y 2026.1.2, los usuarios que no pertenecen a los grupos permitidos de creación de políticas pueden crear widgets funcionales de aceptación de políticas en publicaciones bajo las condiciones adecuadas. Las versiones 2026.3.0-latest.1, 2026.2.1 y 2026.1.2 contienen un parche. Como solución alternativa, deshabilite el plugin discourse-policy deshabilitando la configuración del sitio 'policy_enabled'.
CPE cpe:2.3:a:discourse:discourse:2026.3.0:*:*:*:latest:*:*:*
cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*
First Time Discourse
Discourse discourse
References () https://github.com/discourse/discourse/security/advisories/GHSA-7ph8-vprq-4jrp - () https://github.com/discourse/discourse/security/advisories/GHSA-7ph8-vprq-4jrp - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

19 Mar 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-19 22:16

Updated : 2026-03-23 20:11


NVD link : CVE-2026-29072

Mitre link : CVE-2026-29072

CVE.ORG link : CVE-2026-29072


JSON object : View

Products Affected

discourse

  • discourse
CWE
CWE-862

Missing Authorization