PT-2026-48985 · Discourse · Discourse+1

CVE-2026-45085

·

Published

2026-06-12

·

Updated

2026-06-16

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Discourse versions 2026.1.0-latest through 2026.1.3 Discourse versions 2026.3.0-latest through 2026.3.0 Discourse versions 2026.4.0-latest through 2026.4.0
Description Four authorization and information disclosure issues exist within the chat plugin, with one specifically involving the discourse-calendar plugin. These issues allow users with read-only category permissions to create chat threads and enable authors of self-deleted chat messages to restore them after their channel access has been revoked. Additionally, moderators reviewing flagged chat messages may be shown the current last message of the channel, which often contains unrelated direct message content. Furthermore, calendar event payloads expose the attached chat channel and its last message to viewers who lack chat access, including anonymous users.
Recommendations Update to version 2026.1.4 Update to version 2026.3.1 Update to version 2026.4.1 As a temporary mitigation, disable the chat plugin or the discourse-calendar plugin to prevent exploitation.

Exploit

Fix

Missing Authorization

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2026-45085
CVE-2026-45085
GHSA-RW8J-P2GV-Q33W

Affected Products

Discourse
Discourse Calendar