CVE-2026-26207: DIscourse's discourse-policy plugin lacks post access check
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, discourse-policy plugin allows any authenticated user to interact with policies on posts they do not have permission to view. The PolicyController loads posts by ID without verifying the current user's access, enabling policy group members to accept/unaccept policies on posts in private categories or PMs they cannot see and any authenticated user to enumerate which post IDs have policies attached via differentiated error responses (information disclosure). The issue is patched in versions 2025.12.2, 2026.1.1, and 2026.2.0 by adding a guardian.cansee?(@post) check in the setpost beforeaction, ensuring post visibility is verified before any policy action is processed. As a workaround, disabling the discourse-policy plugin (policyenabled = false) eliminates the vulnerability. There is no other workaround without upgrading.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-26207?
CVE-2026-26207 is classified as a moderate severity vulnerability that affects the Discourse platform.
How do I fix CVE-2026-26207?
To fix CVE-2026-26207, upgrade the `discourse-policy` plugin to versions 2025.12.2, 2026.1.1, or 2026.2.0.
Who is affected by CVE-2026-26207?
Any authenticated user in Discourse can be affected by CVE-2026-26207 if they interact with posts they do not have permission to view.
What is the impact of CVE-2026-26207?
The impact of CVE-2026-26207 allows unauthorized access and manipulation of post policies in Discourse.
Is there a workaround for CVE-2026-26207?
There is no official workaround for CVE-2026-26207; the only remedy is to update the affected plugin to a secure version.