PT-2026-26424 · Discourse · Discourse

·

CVE-2026-33355

·

Published

2026-03-19

·

Updated

2026-03-27

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Discourse versions prior to 2026.3.0-latest.1 Discourse versions prior to 2026.2.1 Discourse versions prior to 2026.1.2
Description Discourse is an open-source discussion platform. The /private-posts API endpoint did not apply post-type visibility filtering in versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2. This allowed regular participants in private message (PM) topics to view whisper posts within those topics, even if they were not intended to have access. The post-type is a parameter that determines the visibility of a post.
Recommendations Update to Discourse version 2026.3.0-latest.1 or later. Update to Discourse version 2026.2.1 or later. Update to Discourse version 2026.1.2 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2026-33355
CVE-2026-33355
GHSA-G4V5-6GFP-3HJQ

Affected Products

Discourse