CVE-2026-27935: Discourse leaks private topic metadata to non-authorized users
Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a vulnerability in an API endpoint that discloses private topic metadata of admin users to moderator users even if the moderators do not have access to the private topics. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch. No known workarounds are available.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27935?
CVE-2026-27935 has been classified as a medium severity vulnerability due to its potential to expose sensitive information.
How do I fix CVE-2026-27935?
To resolve CVE-2026-27935, update your Discourse to version 2026.3.0-latest.1, 2026.2.1, or 2026.1.2 or later.
Which versions of Discourse are affected by CVE-2026-27935?
Discourse versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 are vulnerable to CVE-2026-27935.
What type of data does CVE-2026-27935 expose?
CVE-2026-27935 exposes private topic metadata of admin users to unauthorized moderator users.
Who can be impacted by CVE-2026-27935?
Moderators in Discourse can access confidential metadata of admin users due to CVE-2026-27935, risking information confidentiality.