CVE-2026-31805

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an authorization bypass in the poll plugin allowed authenticated users to vote on, remove votes from, or toggle the open/closed status of polls they did not have access to. By passing post_id as an array (e.g. post_id[]=&post_id[]=), the authorization check resolves to the accessible post while the poll lookup resolves to a different post's poll. This affects the vote, remove_vote, and toggle_status endpoints in DiscoursePoll::PollsController. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*
cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*
cpe:2.3:a:discourse:discourse:2026.3.0:*:*:*:latest:*:*:*

History

24 Mar 2026, 20:17

Type Values Removed Values Added
CPE cpe:2.3:a:discourse:discourse:2026.3.0:*:*:*:latest:*:*:*
cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*
First Time Discourse
Discourse discourse
References () https://github.com/discourse/discourse/commit/1a6b3cdd8939053f485a60a6ea004a40878392c4 - () https://github.com/discourse/discourse/commit/1a6b3cdd8939053f485a60a6ea004a40878392c4 - Patch
References () https://github.com/discourse/discourse/security/advisories/GHSA-fgxm-prjv-g823 - () https://github.com/discourse/discourse/security/advisories/GHSA-fgxm-prjv-g823 - Vendor Advisory
Summary
  • (es) Discourse es una plataforma de discusión de código abierto. Antes de las versiones 2026.3.0-latest.1, 2026.2.1 y 2026.1.2, una omisión de autorización en el plugin de encuestas permitía a usuarios autenticados votar en, eliminar votos de, o alternar el estado abierto/cerrado de encuestas a las que no tenían acceso. Al pasar post_id como un array (p. ej., post_id[]=&post_id[]=), la verificación de autorización se resuelve al post accesible mientras que la búsqueda de la encuesta se resuelve a la encuesta de un post diferente. Esto afecta a los endpoints vote, remove_vote y toggle_status en DiscoursePoll::PollsController. Las versiones 2026.3.0-latest.1, 2026.2.1 y 2026.1.2 contienen un parche.

20 Mar 2026, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-20 03:15

Updated : 2026-03-24 20:17


NVD link : CVE-2026-31805

Mitre link : CVE-2026-31805

CVE.ORG link : CVE-2026-31805


JSON object : View

Products Affected

discourse

  • discourse
CWE
CWE-20

Improper Input Validation

CWE-863

Incorrect Authorization