CVE-2025-68933: Discourse non-admin moderators can exfiltrate private content via post ownership transfer

Published Jan 28, 2026
·
Updated

Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, non-admin moderators with the moderatorschangepostownership setting enabled can change ownership of posts in private messages and restricted categories they cannot access, then export their data to view the content. This is a broken access control vulnerability affecting sites that grant moderators post ownership transfer permissions. This issue is patched in versions 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0. The patch adds visibility checks for both the topic and posts before allowing ownership transfer. As a workaround, disable the moderatorschangepostownership site setting to prevent non-admin moderators from using the post ownership transfer feature.

Affected Software

5 affected components
Discourse Discourse<3.5.4, <2025.11.2, <2025.12.1, <2026.1.0
Discourse Discourse<3.5.4
Discourse Discourse>=2025.11.0<2025.11.2
Discourse Discourse=2025.12.0
Discourse Discourse=2026.1.0

Event History

Jan 28, 2026
CVE Published
via MITRE·07:17 PM
Data Sourced
via MITRE·07:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-68933?

CVE-2025-68933 is classified as a high severity vulnerability due to the risk of unauthorized access to private content by non-admin moderators.

2

How do I fix CVE-2025-68933?

To remediate CVE-2025-68933, upgrade to Discourse versions 3.5.4, 2025.11.2, 2025.12.1, or 2026.1.0 or disable the 'moderators_change_post_ownership' setting.

3

Who is affected by CVE-2025-68933?

CVE-2025-68933 affects non-admin moderators in Discourse installations prior to the specified fixed versions.

4

What does CVE-2025-68933 exploit?

CVE-2025-68933 exploits the ability of non-admin moderators to change post ownership, allowing them to exfiltrate private content.

5

What is the impact of CVE-2025-68933?

The impact of CVE-2025-68933 includes potential unauthorized access and disclosure of sensitive private content within Discourse.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203