CVE-2026-33424: PM access granted through invites after access revocation
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an attacker can grant access to a private message topic through invites even after they lose access to that PM. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch. No known workarounds are available.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33424?
CVE-2026-33424 is considered a significant security vulnerability as it allows unauthorized users to access private message topics through invites even after access has been revoked.
How do I fix CVE-2026-33424?
To fix CVE-2026-33424, update Discourse to version 2026.3.0-latest.1, 2026.2.1, or 2026.1.2 or later.
What types of software are affected by CVE-2026-33424?
CVE-2026-33424 affects Discourse versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2.
Can I still receive invites to private messages if I lost access due to CVE-2026-33424?
Yes, an attacker can still grant access through invites to private messages even after access has been revoked, making it a critical issue.
What actions can I take to protect against CVE-2026-33424 until I can update?
To protect against CVE-2026-33424, restrict the ability of users to send invites to sensitive private message topics until the software is updated.