CVE-2026-21865: Discourse topic conversion permission vulnerability for moderators
Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, moderators can convert some personal messages to public topics when they shouldn't have access. This issue is patched in versions 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0. As a workaround, site admin can temporarily revoke the moderation role from untrusted moderators or remove the moderator group from the "personal message enabled groups" site setting until the Discourse instance has been upgraded to a version that has been patched.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21865?
CVE-2026-21865 has a moderate severity level as it allows moderators to improperly convert personal messages into public topics.
How do I fix CVE-2026-21865?
To fix CVE-2026-21865, upgrade to Discourse versions 3.5.4, 2025.11.2, 2025.12.1, or 2026.1.0, which have addressed this vulnerability.
Which versions of Discourse are affected by CVE-2026-21865?
Discourse versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 are vulnerable to CVE-2026-21865.
What type of vulnerability is CVE-2026-21865?
CVE-2026-21865 is a permission vulnerability that affects the topic conversion capabilities of moderators.
Who is affected by CVE-2026-21865?
Moderators using affected versions of Discourse may improperly have the ability to convert personal messages to public topics due to CVE-2026-21865.