πŸ” CVE Alert

CVE-2026-55704

MEDIUM 4.3

Discourse: Shared-draft titles and excerpts leak through group post serialization

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

Discourse is an open-source discussion platform. Prior o 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, users who were allowed to view a group’s activity, but were not permitted to see shared drafts, could still receive shared-draft entries through the group posts and group mentions endpoints. This could disclose shared-draft topic titles and post excerpt/content, resulting in an information disclosure of unpublished draft material. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.

CWE CWE-862
Vendor discourse
Product discourse
Published Aug 17, 2026
Last Updated Aug 17, 2026
Stay Ahead of the Next One

Get instant alerts for discourse discourse

Be the first to know when new medium vulnerabilities affecting discourse discourse are published β€” delivered to Slack, Telegram or Discord.

Get Free Alerts β†’ Free Β· No credit card Β· 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

discourse / discourse
< 2026.1.6 >= 2026.5.0-latest, < 2026.5.2 >= 2026.6.0-latest, < 2026.6.1

References

NVD β†— CVE.org β†— EPSS Data β†—
github.com: https://github.com/discourse/discourse/security/advisories/GHSA-fxw4-38v9-76v8