๐Ÿ” CVE Alert

CVE-2025-68666

UNKNOWN 0.0

Discourse users archives leaked to users with moderation privileges

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, users archives are viewable by users with moderation privileges even though moderators should not have access to the archives. Private topic/post content made by the users are leaked through the archives leading to a breach of confidentiality. This issue is patched in versions 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0. To work around this problem, a site admin can temporarily revoke the moderation role from all moderators until the Discourse instance has been upgraded to a version that has been patched.

CWE CWE-863
Vendor discourse
Product discourse
Published Jan 28, 2026
Last Updated Feb 26, 2026
Stay Ahead of the Next One

Get instant alerts for discourse discourse

Be the first to know when new unknown vulnerabilities affecting discourse discourse are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

discourse / discourse
< 3.5.4 >= 2025.11.0-latest, < 2025.11.2 >= 2025.12.0-latest, < 2025.12.1 >= 2026.1.0-latest, < 2026.1.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/discourse/discourse/security/advisories/GHSA-xmvw-jjqq-25mv