CVE-2026-27152: DIscourse has DM communication-preference bypass when adding members
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, DM communication-preference bypass when adding members via Chat::AddUsersToChannel — a user could add targets who have blocked/ignored/muted them to an existing DM channel, bypassing per-recipient PM restrictions that are enforced during DM channel creation. Versions 2025.12.2, 2026.1.1, and 2026.2.0 patch the issue. No known workarounds are available.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27152?
CVE-2026-27152 is classified as a medium-severity vulnerability due to the potential for unauthorized DM channel access.
How do I fix CVE-2026-27152?
To fix CVE-2026-27152, upgrade to Discourse versions 2025.12.2, 2026.1.1, or 2026.2.0.
What vulnerable software versions are affected by CVE-2026-27152?
Discourse versions prior to 2025.12.2, 2026.1.1, and 2026.2.0 are affected by CVE-2026-27152.
What specific issue does CVE-2026-27152 address?
CVE-2026-27152 addresses a DM communication-preference bypass that allows users to add blocked contacts to DM channels.
Is user data at risk due to CVE-2026-27152?
Yes, user data may be at risk as this vulnerability could allow blocked users to access previously restricted DM channels.