CVE-2026-33428: Discourse Allows Unauthorized Access to Deleted Posts Index via Group Membership
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a non-staff user with elevated group membership could access deleted posts belonging to any user due to an overly broad authorization check on the deleted posts index endpoint. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch. No known workarounds are available.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33428?
CVE-2026-33428 has a high severity level due to potential unauthorized access to deleted posts.
How do I fix CVE-2026-33428?
To fix CVE-2026-33428, update your Discourse installation to version 2026.3.0-latest.1, 2026.2.1, or 2026.1.2 or later.
Who is affected by CVE-2026-33428?
Non-staff users with elevated group membership on Discourse are affected by CVE-2026-33428.
What type of vulnerability is CVE-2026-33428?
CVE-2026-33428 is an access control vulnerability that allows unauthorized users to view deleted posts.
When was CVE-2026-33428 disclosed?
CVE-2026-33428 was disclosed prior to the release of the fixed versions mentioned in the advisory.