CVE-2026-30888: Discourse has moderator privilege escalation via arbitrary post_id in suspend/silence endpoint
Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 allow a moderator to edit site policy documents (ToS, guidelines, privacy policy) that they are explicitly prohibited from modifying. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch. No known workarounds are available.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-30888?
CVE-2026-30888 is rated as a moderate severity vulnerability due to the potential for moderator privilege escalation.
How do I fix CVE-2026-30888?
To fix CVE-2026-30888, upgrade to the latest versions of Discourse: 2026.3.0-latest.1, 2026.2.1, or 2026.1.2.
Who is affected by CVE-2026-30888?
CVE-2026-30888 affects Discourse versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2.
What type of vulnerability is CVE-2026-30888?
CVE-2026-30888 is a privilege escalation vulnerability that allows unauthorized editing of site policy documents.
What components are vulnerable in CVE-2026-30888?
CVE-2026-30888 specifically affects the suspend/silence endpoint of the Discourse platform.