PT-2026-48978 · Discourse · Discourse
CVE-2026-44780
·
Published
2026-06-12
·
Updated
2026-06-16
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Discourse versions 2026.1.0 through 2026.1.3
Discourse versions 2026.3.0
Discourse versions 2026.4.0
Description
The
ReviewableQueuedPostSerializer unconditionally includes the raw email payload for posts received via incoming email. This allows members of category moderation groups accessing the review queue to read the complete inbound email source, including headers, sender trace, MUA, and body, bypassing the view raw email allowed groups trust boundary that normally restricts access to the raw-email endpoint.Recommendations
Update versions 2026.1.0 through 2026.1.3 to 2026.1.4.
Update version 2026.3.0 to 2026.3.1.
Update version 2026.4.0 to 2026.4.1.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Discourse