CVE-2026-30889: Discourse has Unauthorized Post Data Exposure in discourse-user-notes
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a moderator could exploit insufficient authorization checks to access metadata of posts they should not have permission to view. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-30889?
CVE-2026-30889 is classified as a medium severity vulnerability due to its potential for unauthorized access to post metadata.
How do I fix CVE-2026-30889?
To fix CVE-2026-30889, upgrade Discourse to versions 2026.3.0-latest.1, 2026.2.1, or 2026.1.2 or later.
Who is affected by CVE-2026-30889?
CVE-2026-30889 affects all users of Discourse versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2.
What kind of exposure does CVE-2026-30889 cause?
CVE-2026-30889 causes unauthorized post data exposure, allowing moderators to access metadata they should not be able to.
What are the potential impacts of CVE-2026-30889?
The potential impacts of CVE-2026-30889 include privacy violations and unauthorized insights into user discussions.