CVE-2026-46413

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, regular users could route direct S3 multipart uploads through ExternalUploadManager into the admin backup store. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*
cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*
cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*
cpe:2.3:a:discourse:discourse:2026.6.0:*:*:*:latest:*:*:*

History

14 Jul 2026, 20:41

Type Values Removed Values Added
CPE cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*
cpe:2.3:a:discourse:discourse:2026.6.0:*:*:*:latest:*:*:*
First Time Discourse discourse
Discourse
References () https://github.com/discourse/discourse/commit/1f1ded8dd361d81786bff17b35e1138d6ee299c0 - () https://github.com/discourse/discourse/commit/1f1ded8dd361d81786bff17b35e1138d6ee299c0 - Patch
References () https://github.com/discourse/discourse/commit/7ddde266617b452152c1bf5f903f6c07be38fc40 - () https://github.com/discourse/discourse/commit/7ddde266617b452152c1bf5f903f6c07be38fc40 - Patch
References () https://github.com/discourse/discourse/commit/a53df26dcf7e50ce2b20bfd5454a0c9d44b8fc7d - () https://github.com/discourse/discourse/commit/a53df26dcf7e50ce2b20bfd5454a0c9d44b8fc7d - Patch
References () https://github.com/discourse/discourse/commit/abaa664c5df84026efb2ca264ba0f5586c3f2b01 - () https://github.com/discourse/discourse/commit/abaa664c5df84026efb2ca264ba0f5586c3f2b01 - Patch
References () https://github.com/discourse/discourse/releases/tag/v2026.1.5 - () https://github.com/discourse/discourse/releases/tag/v2026.1.5 - Release Notes
References () https://github.com/discourse/discourse/releases/tag/v2026.4.2 - () https://github.com/discourse/discourse/releases/tag/v2026.4.2 - Release Notes
References () https://github.com/discourse/discourse/releases/tag/v2026.5.1 - () https://github.com/discourse/discourse/releases/tag/v2026.5.1 - Release Notes
References () https://github.com/discourse/discourse/releases/tag/v2026.6.0 - () https://github.com/discourse/discourse/releases/tag/v2026.6.0 - Release Notes
References () https://github.com/discourse/discourse/security/advisories/GHSA-3mvf-q9rg-w6m7 - () https://github.com/discourse/discourse/security/advisories/GHSA-3mvf-q9rg-w6m7 - Vendor Advisory, Mitigation

09 Jul 2026, 22:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-09 22:17

Updated : 2026-07-14 20:41


NVD link : CVE-2026-46413

Mitre link : CVE-2026-46413

CVE.ORG link : CVE-2026-46413


JSON object : View

Products Affected

discourse

  • discourse
CWE
CWE-862

Missing Authorization