CVE-2026-33291: Discourse user can create Zendesk tickets even when it does not have access to topic
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, moderators can create Zendesk tickets for topics they do not have access to view. This affects all forums that use the Zendesk plugin. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch. No known workarounds are available.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33291?
CVE-2026-33291 is considered a moderate severity vulnerability due to its impact on user access control.
How do I fix CVE-2026-33291?
To fix CVE-2026-33291, upgrade Discourse to version 2026.3.0-latest.1 or later, or to versions 2026.2.1 or 2026.1.2.
What specific issue does CVE-2026-33291 address?
CVE-2026-33291 addresses a vulnerability where moderators can create Zendesk tickets for topics they shouldn't have access to.
Which versions of Discourse are affected by CVE-2026-33291?
CVE-2026-33291 affects all versions of Discourse prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2.
Is the Zendesk plugin related to CVE-2026-33291?
Yes, the vulnerability specifically affects all forums that utilize the Zendesk plugin within Discourse.