PT-2026-105082 · Bitnami · Discourse

Published

2026-10-01

·

Updated

2026-10-01

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, authenticated users could supply unescaped SQL LIKE metacharacters to upload-resolution patterns, causing wildcard input to select unrelated upload records instead of matching a literal identifier. The affected upload metadata, URL-lookup, and cooked-video-placeholder paths could resolve uploads the user was not authorized to access. This allowed disclosure of restricted metadata, including original filenames and secure-upload paths, without modifying the upload records. This issue is fixed in versions 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BIT-DISCOURSE-2026-91133

Affected Products

Discourse