PT-2026-48985 · Discourse · Discourse+1
CVE-2026-45085
·
Published
2026-06-12
·
Updated
2026-06-16
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Discourse versions 2026.1.0-latest through 2026.1.3
Discourse versions 2026.3.0-latest through 2026.3.0
Discourse versions 2026.4.0-latest through 2026.4.0
Description
Four authorization and information disclosure issues exist within the chat plugin, with one specifically involving the discourse-calendar plugin. These issues allow users with read-only category permissions to create chat threads and enable authors of self-deleted chat messages to restore them after their channel access has been revoked. Additionally, moderators reviewing flagged chat messages may be shown the current
last message of the channel, which often contains unrelated direct message content. Furthermore, calendar event payloads expose the attached chat channel and its last message to viewers who lack chat access, including anonymous users.Recommendations
Update to version 2026.1.4
Update to version 2026.3.1
Update to version 2026.4.1
As a temporary mitigation, disable the chat plugin or the discourse-calendar plugin to prevent exploitation.
Exploit
Fix
Missing Authorization
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Discourse
Discourse Calendar