PT-2026-48978 · Discourse · Discourse

CVE-2026-44780

·

Published

2026-06-12

·

Updated

2026-06-16

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Discourse versions 2026.1.0 through 2026.1.3 Discourse versions 2026.3.0 Discourse versions 2026.4.0
Description The ReviewableQueuedPostSerializer unconditionally includes the raw email payload for posts received via incoming email. This allows members of category moderation groups accessing the review queue to read the complete inbound email source, including headers, sender trace, MUA, and body, bypassing the view raw email allowed groups trust boundary that normally restricts access to the raw-email endpoint.
Recommendations Update versions 2026.1.0 through 2026.1.3 to 2026.1.4. Update version 2026.3.0 to 2026.3.1. Update version 2026.4.0 to 2026.4.1.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2026-44780
CVE-2026-44780
GHSA-H2JR-WHPX-6W63

Affected Products

Discourse