CVE-2026-30888

Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 allow a moderator to edit site policy documents (ToS, guidelines, privacy policy) that they are explicitly prohibited from modifying. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch. No known workarounds are available.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*
cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*
cpe:2.3:a:discourse:discourse:2026.3.0:*:*:*:latest:*:*:*

History

24 Mar 2026, 19:59

Type Values Removed Values Added
Summary
  • (es) Discourse es una plataforma de discusión de código abierto. Las versiones anteriores a 2026.3.0-latest.1, 2026.2.1 y 2026.1.2 permiten a un moderador editar documentos de política del sitio (Términos de Servicio, directrices, política de privacidad) que tienen explícitamente prohibido modificar. Las versiones 2026.3.0-latest.1, 2026.2.1 y 2026.1.2 contienen un parche. No se conocen soluciones alternativas disponibles.
First Time Discourse
Discourse discourse
References () https://github.com/discourse/discourse/security/advisories/GHSA-jj9p-p7m6-jq96 - () https://github.com/discourse/discourse/security/advisories/GHSA-jj9p-p7m6-jq96 - Vendor Advisory
CPE cpe:2.3:a:discourse:discourse:2026.3.0:*:*:*:latest:*:*:*
cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*

20 Mar 2026, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-20 03:15

Updated : 2026-03-24 19:59


NVD link : CVE-2026-30888

Mitre link : CVE-2026-30888

CVE.ORG link : CVE-2026-30888


JSON object : View

Products Affected

discourse

  • discourse
CWE
CWE-269

Improper Privilege Management