CVE-2026-27936: Discourse discloses restricted post-action counts to non-privileged users
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a restriction bypass allows restricted post action counts to be disclosed to non-privileged users through a carefully crafted request. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch. No known workarounds are available.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27936?
CVE-2026-27936 has been rated as a moderate severity vulnerability due to its potential to expose restricted information to unauthorized users.
How do I fix CVE-2026-27936?
To fix CVE-2026-27936, update your Discourse instance to version 2026.3.0-latest.1, 2026.2.1, or 2026.1.2.
What versions of Discourse are affected by CVE-2026-27936?
CVE-2026-27936 affects Discourse versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2.
What type of information is exposed in CVE-2026-27936?
CVE-2026-27936 allows non-privileged users to see restricted post-action counts that should not be accessible to them.
Is there a workaround for CVE-2026-27936?
There is no official workaround for CVE-2026-27936; the recommended action is to apply the available software updates.