CVE-2026-33074: Discourse: Vulnerability in discourse-subscriptions plugin allowing users to self-grant to higher tier subscriptions
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, a user may be able to purchase a lower tier subscription but grant themselves the benefits that comes along with a higher tier subscription. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Discourse (discourse-subscriptions plugin)to a version that resolves this vulnerability.Fixed in 2026.1.3 - Upgrade
Upgrade
Discourse (discourse-subscriptions plugin)to a version that resolves this vulnerability.Fixed in 2026.2.2 - Upgrade
Upgrade
Discourse (discourse-subscriptions plugin)to a version that resolves this vulnerability.Fixed in 2026.3.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33074?
The severity of CVE-2026-33074 is classified as high due to its potential impact on subscription management in Discourse.
How do I fix CVE-2026-33074?
To fix CVE-2026-33074, upgrade to Discourse version 2026.1.3 or later, 2026.2.2 or later, or 2026.3.0 or later.
What versions of Discourse are affected by CVE-2026-33074?
CVE-2026-33074 affects Discourse versions from 2026.1.0 to before 2026.1.3, from 2026.2.0 to before 2026.2.2, and versions up to but not including 2026.3.0.
What does CVE-2026-33074 allow users to do?
CVE-2026-33074 allows users to self-grant access to higher tier subscriptions without proper authorization.
Is there a workaround for CVE-2026-33074?
There are no specific workarounds recommended for CVE-2026-33074; the best course of action is to apply the updates.