CVE-2026-84302

Source
https://cve.org/CVERecord?id=CVE-2026-84302
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-84302.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-84302
Aliases
  • GHSA-3rx9-fqgh-wfpc
Published
2026-09-24T16:49:56Z
Modified
2026-09-26T03:47:58Z
Severity
  • 4.2 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Discourse: Non-participant moderators can read, edit, and delete PM content through Discourse AI reviewables
Details

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, Discourse AI reviewables associated with private messages could appear in the moderator review queue of a moderator who was not a participant in the message. Reviewable visibility filtering did not restrict private-message reviewables to the audience permitted to access the underlying private-message topic, allowing the moderator to read otherwise confidential content. Depending on the available reviewable action, the moderator could also modify the private message by closing its topic or deleting a post. Exploitation requires an authenticated moderator account and a pre-existing Discourse AI reviewable associated with a private message. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-862"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84302.json"
}
References

Affected packages

Git / github.com/discourse/discourse

Affected ranges

Type
GIT
Repo
https://github.com/discourse/discourse
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "2026.7.0"
        },
        {
            "introduced":  "2026.6.0-latest"
        },
        {
            "fixed":  "2026.6.1"
        },
        {
            "introduced":  "2026.5.0-latest"
        },
        {
            "fixed":  "2026.5.2"
        },
        {
            "introduced":  "2026.1.0-latest"
        },
        {
            "fixed":  "2026.1.6"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

Other
_gh-attach-assets
esr
stable
v2026.*
v2026.1.0
v2026.1.0-latest
v2026.1.1
v2026.1.2
v2026.1.3
v2026.1.4
v2026.1.5
v2026.5.0
v2026.5.0-latest
v2026.5.0-latest.1
v2026.5.1
v2026.6.0
v2026.6.0-latest
v2026.7.0-latest

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-84302.json"