CVE-2026-33355: Discourse filters whisper posts from private-posts feed
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the /private-posts endpoint did not apply post-type visibility filtering, allowing regular PM participants to see whisper posts in PM topics they had access to. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch. No known workarounds are available.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33355?
CVE-2026-33355 is considered a moderate severity vulnerability due to its impact on privacy within private messaging.
How do I fix CVE-2026-33355?
To fix CVE-2026-33355, upgrade your Discourse instance to versions 2026.3.0-latest.1, 2026.2.1, or 2026.1.2 or later.
What vulnerability does CVE-2026-33355 address?
CVE-2026-33355 addresses a flaw where the /private-posts endpoint did not apply the correct visibility filtering for whisper posts.
Who is affected by CVE-2026-33355?
Users running versions of Discourse prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 are at risk with CVE-2026-33355.
What type of vulnerability is CVE-2026-33355?
CVE-2026-33355 is a privacy and access control vulnerability in the Discourse forum software.