CVE-2026-27491: Discourse has a bypass of official warnings messages by non-staff users
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a type coercion issue in a post actions API endpoint allowed non-staff users to issue warnings to other users. Warnings are a staff-only moderation feature. The vulnerability required the attacker to be a logged-in user and to send a specifically crafted request. No data exposure or privilege escalation beyond the ability to create unauthorized user warnings was possible. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch. No known workarounds are available.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27491?
CVE-2026-27491 has a moderate severity level as it allows non-staff users to bypass warning restrictions.
How do I fix CVE-2026-27491?
To mitigate CVE-2026-27491, upgrade Discourse to version 2026.3.0-latest.1, 2026.2.1, or 2026.1.2.
What systems are affected by CVE-2026-27491?
CVE-2026-27491 affects all versions of Discourse prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2.
What is the nature of the vulnerability in CVE-2026-27491?
CVE-2026-27491 involves a type coercion issue in the post actions API endpoint that allows non-staff users to issue warnings.
Who is responsible for addressing CVE-2026-27491?
The Discourse development team is responsible for addressing CVE-2026-27491 via software updates.