CVE-2026-28218: Discourse's Fail-Open Access Control in Data Explorer Plugin Allows Unauthorized SQL Query Execution
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, fail-open access control in Data Explorer plugin allows any authenticated user to execute SQL queries that have no explicit group assignments, including built-in system queries. Versions 2025.12.2, 2026.1.1, and 2026.2.0 patch the issue. As a workaround, either explicitly set group permissions on each Data Explorer query that doesn't have permissions, or disable discourse-data-explorer plugin.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28218?
CVE-2026-28218 is classified as a high severity vulnerability due to its potential to allow unauthorized SQL query execution.
How do I fix CVE-2026-28218?
To fix CVE-2026-28218, upgrade to Discourse version 2025.12.2, 2026.1.1, or 2026.2.0 to mitigate the vulnerability.
What does CVE-2026-28218 exploit?
CVE-2026-28218 exploits a fail-open access control vulnerability in the Data Explorer plugin of Discourse.
What impact does CVE-2026-28218 have on my Discourse installation?
CVE-2026-28218 allows any authenticated user to execute arbitrary SQL queries, potentially compromising database integrity.
Which versions of Discourse are affected by CVE-2026-28218?
CVE-2026-28218 affects Discourse versions prior to 2025.12.2, 2026.1.1, and 2026.2.0.