CVE-2026-32099: Discourse prevents hidden profile data leak via user onebox
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, when a user has hideprofile enabled, their bio, location, and website were still exposed through the user onebox preview. An authenticated user could request a onebox for a hidden user's profile URL and receive their hidden profile fields (bio, location, website) in the response. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch. No known workarounds are available.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32099?
CVE-2026-32099 is classified as a moderate severity vulnerability that risks exposing hidden user profile information.
What are the affected versions in CVE-2026-32099?
CVE-2026-32099 affects Discourse versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2.
How do I fix CVE-2026-32099?
To remediate CVE-2026-32099, upgrade your Discourse installation to version 2026.3.0-latest.1 or later.
What data is exposed in CVE-2026-32099?
CVE-2026-32099 exposes user bio, location, and website information even when users have 'hide_profile' enabled.
How can I check if I'm affected by CVE-2026-32099?
To determine if you are affected by CVE-2026-32099, verify your Discourse version against the specified vulnerable versions.