CVE-2026-27021: Discourse: Poll voters endpoint lacked post visibility checks
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, the voters endpoint in the poll plugin lacked post visibility checks which allowed unauthorized access to voters details of polls in any post. Versions 2025.12.2, 2026.1.1, and 2026.2.0 patch the issue. No known workarounds are available.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27021?
CVE-2026-27021 has been assessed as a high severity vulnerability due to its potential to expose sensitive voter details.
How do I fix CVE-2026-27021?
To fix CVE-2026-27021, update your Discourse installation to version 2025.12.2, 2026.1.1, or 2026.2.0.
What components are affected by CVE-2026-27021?
CVE-2026-27021 affects the voters endpoint in the poll plugin of Discourse prior to the specified patched versions.
What type of vulnerability is CVE-2026-27021?
CVE-2026-27021 is a security vulnerability that allows unauthorized access to voter details in polls.
Who is impacted by CVE-2026-27021?
Users of Discourse versions prior to 2025.12.2, 2026.1.1, and 2026.2.0 are impacted by CVE-2026-27021.