CVE-2026-29072: Discourse missing permission check for policy creation in discourse-policy
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, users who do not belong to the allowed policy creation groups can create functional policy acceptance widgets in posts under the right conditions. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch. As a workaround, disable the discourse-policy plugin by disabling the policyenabled site setting.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-29072?
CVE-2026-29072 is considered a high-severity vulnerability due to improper permission checks.
How do I fix CVE-2026-29072?
To fix CVE-2026-29072, upgrade Discourse to version 2026.3.0-latest.1, 2026.2.1, or 2026.1.2.
What are the risks associated with CVE-2026-29072?
The risks of CVE-2026-29072 include unauthorized policy creation by users not in allowed groups, leading to potential misuse.
Which versions of Discourse are affected by CVE-2026-29072?
CVE-2026-29072 affects Discourse versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2.
Is there a workaround for CVE-2026-29072?
There are no official workarounds provided for CVE-2026-29072, and upgrading is the recommended solution.