PT-2026-48982 · Discourse · Discourse

CVE-2026-44785

·

Published

2026-06-12

·

Updated

2026-06-16

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Discourse versions 2026.1.0 through 2026.1.3 Discourse versions 2026.3.0 Discourse versions 2026.4.0
Description The AI explain helper fails to verify the can see? permission on the reply to post of a post being explained. This allows an authenticated user with access to the AI helper to read the raw contents of a hidden parent post by invoking the explain feature on a reply to that parent post.
Recommendations Update to version 2026.1.4 Update to version 2026.3.1 Update to version 2026.4.1

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2026-44785
CVE-2026-44785
GHSA-7H76-FWXC-J586

Affected Products

Discourse