CVE-2026-32244: Discourse: Cached outdated summaries can leak removed content
Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, outdated cached AI summaries can leak removed content to anonymous and unprivileged users who cannot regenerate summaries. This issue has been fixed in versions 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1. To work around this issue, restrict summary generation by tightening the allowed groups on the summarization Personas.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Discourseto a version that resolves this vulnerability.Fixed in 2026.1.4 - Upgrade
Upgrade
Discourseto a version that resolves this vulnerability.Fixed in 2026.3.1 - Upgrade
Upgrade
Discourseto a version that resolves this vulnerability.Fixed in 2026.4.1 - Upgrade
Upgrade
Discourseto a version that resolves this vulnerability.Fixed in 2026.5.0-latest.1 - Configuration
To work around the issue, restrict summary generation by tightening the allowed groups on the summarization Personas so that anonymous/unprivileged users cannot regenerate summaries and access cached outdated AI summaries.
Discourse summarization Personas allowed groups for summary generation = tighten allowed groups
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32244?
CVE-2026-32244 is classified as a medium severity vulnerability due to its potential to expose sensitive content.
How do I fix CVE-2026-32244?
To fix CVE-2026-32244, you should upgrade to Discourse versions 2026.1.4, 2026.3.1, 2026.4.1, or 2026.5.0-latest.1.
Who is affected by CVE-2026-32244?
CVE-2026-32244 affects users running Discourse versions prior to 2026.1.4, 2026.3.1, 2026.4.1, and 2026.5.0-latest.1.
What type of content can be leaked due to CVE-2026-32244?
CVE-2026-32244 can leak removed content through outdated cached AI summaries.
Are anonymous users at risk with CVE-2026-32244?
Yes, anonymous and unprivileged users may gain access to sensitive information due to CVE-2026-32244.