CVE-2026-33423: Discourse staff can modify any user's group notification level
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, staff can modify any user's group notification level. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch. No known workarounds are available.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33423?
CVE-2026-33423 has been classified as a moderate severity vulnerability due to potential unauthorized changes to user notification settings.
How do I fix CVE-2026-33423?
To fix CVE-2026-33423, update your Discourse installation to version 2026.3.0-latest.1, 2026.2.1, or 2026.1.2.
Who is affected by CVE-2026-33423?
All users of Discourse versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 are affected by CVE-2026-33423.
What are the implications of CVE-2026-33423 for Discourse staff?
CVE-2026-33423 allows Discourse staff to modify any user's group notification level, potentially leading to unauthorized changes.
What types of notifications can be altered due to CVE-2026-33423?
CVE-2026-33423 allows staff to change the notification levels for group notifications, which may affect how users receive updates.