CVE-2026-33251: Discourse has a Hidden Solved topics permission bypass
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an authorization bypass vulnerability in hidden Solved topics may allow unauthorized users to accept or unaccept solutions. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch. As a workaround, ensure only trusted users are part of the Site Setting for acceptallsolutionsallowedgroups.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33251?
CVE-2026-33251 is classified as a medium-severity authorization bypass vulnerability.
How do I fix CVE-2026-33251?
To fix CVE-2026-33251, you need to update Discourse to version 2026.3.0-latest.1, 2026.2.1, or 2026.1.2 or later.
What impact does CVE-2026-33251 have on Discourse users?
CVE-2026-33251 allows unauthorized users to accept or unaccept solutions in hidden Solved topics, potentially misleading users.
Which versions of Discourse are affected by CVE-2026-33251?
CVE-2026-33251 affects Discourse versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2.
Is there a patch available for CVE-2026-33251?
Yes, patches for CVE-2026-33251 are included in Discourse versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2.