CVE-2026-31805: Discourse has a poll authorization bypass via post_id array parameter

Published Mar 20, 2026
·
Updated

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an authorization bypass in the poll plugin allowed authenticated users to vote on, remove votes from, or toggle the open/closed status of polls they did not have access to. By passing postid as an array (e.g. postid[]=&postid[]=), the authorization check resolves to the accessible post while the poll lookup resolves to a different post's poll. This affects the vote, removevote, and togglestatus endpoints in DiscoursePoll::PollsController. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch.

Affected Software

4 affected components
Discourse Discourse<2026.3.0-latest.1, <2026.2.1, <2026.1.2
Discourse Discourse>=2026.1.0<2026.1.2
Discourse Discourse>=2026.2.0<2026.2.1
Discourse Discourse=2026.3.0

Event History

Mar 20, 2026
CVE Published
via MITRE·03:07 AM
Data Sourced
via MITRE·03:07 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 AM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-31805?

CVE-2026-31805 is classified as a medium severity vulnerability due to its potential impact on user authorization.

2

How do I fix CVE-2026-31805?

To fix CVE-2026-31805, update your Discourse installation to version 2026.3.0-latest.1, 2026.2.1, or 2026.1.2 or later.

3

What is the nature of the vulnerability identified in CVE-2026-31805?

CVE-2026-31805 is an authorization bypass vulnerability in the poll plugin of Discourse that allows unauthorized users to manipulate votes.

4

Which versions of Discourse are affected by CVE-2026-31805?

CVE-2026-31805 affects Discourse versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2.

5

Can I manage votes using the poll plugin if I am affected by CVE-2026-31805?

Yes, if your Discourse installation is affected by CVE-2026-31805, authenticated users may unfairly manage votes in polls.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203