CVE-2026-33300: Discourse: Hidden group names and access metadata are exposed to moderators through the `category-chatables` endpoint
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, an authorization bypass in the Category Chatables Controller show action allowed moderators to get information on hidden groups names and user count. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Discourseto a version that resolves this vulnerability.Fixed in 2026.1.3 - Upgrade
Upgrade
Discourseto a version that resolves this vulnerability.Fixed in 2026.2.2 - Upgrade
Upgrade
Discourseto a version that resolves this vulnerability.Fixed in 2026.3.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33300?
The severity of CVE-2026-33300 is classified as medium due to the exposure of sensitive metadata.
How do I fix CVE-2026-33300?
To fix CVE-2026-33300, upgrade Discourse to version 2026.1.3 or later, 2026.2.2 or later, or ensure you are using version 2026.3.0 or higher.
What software versions are affected by CVE-2026-33300?
CVE-2026-33300 affects Discourse versions from 2026.1.0 to before 2026.1.3, 2026.2.0 to before 2026.2.2, and up to 2026.3.0.
Who is impacted by CVE-2026-33300?
Moderators using affected versions of Discourse can be impacted by CVE-2026-33300 as they may see hidden group names and access metadata.
Is there a known exploit for CVE-2026-33300?
Currently, no known exploits for CVE-2026-33300 have been reported, but the vulnerability allows unauthorized access to sensitive information.