CVE-2026-30891: Discourse hasUnauthorized Exposure of Private User Action Types
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a user could access another user's private activity due to insufficient authorization checks in the user actions endpoint. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-30891?
CVE-2026-30891 is considered a medium severity vulnerability due to unauthorized exposure of private user actions.
How do I fix CVE-2026-30891?
To fix CVE-2026-30891, upgrade to Discourse version 2026.3.0-latest.1, 2026.2.1, or 2026.1.2 or later.
What are the affected versions for CVE-2026-30891?
CVE-2026-30891 affects all Discourse versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2.
What type of vulnerability is CVE-2026-30891?
CVE-2026-30891 is classified as an unauthorized access vulnerability, allowing users to view private activities of other users.
Can CVE-2026-30891 be exploited remotely?
Yes, CVE-2026-30891 can be exploited remotely by unauthorized users accessing specific endpoints.