CVE-2026-34154: Discourse has a subscription access bypass in its discourse-subscriptions plugin
Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, a vulnerability in the discourse-subscriptions plugin allows users to gain access to subscription-gated groups without completing payment. This issue has been fixed in versions 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
discourse/discourse-subscriptionsto a version that resolves this vulnerability.Fixed in 2026.1.4 - Upgrade
Upgrade
discourse/discourse-subscriptionsto a version that resolves this vulnerability.Fixed in 2026.3.1 - Upgrade
Upgrade
discourse/discourse-subscriptionsto a version that resolves this vulnerability.Fixed in 2026.4.1 - Upgrade
Upgrade
discourse/discourse-subscriptionsto a version that resolves this vulnerability.Fixed in 2026.5.0-latest.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34154?
The severity of CVE-2026-34154 is rated low with a CVSS score of 4.0.
How do I fix CVE-2026-34154?
To fix CVE-2026-34154, update to Discourse versions 2026.1.4, 2026.3.1, 2026.4.1, or 2026.5.0-latest.1.
What impact does CVE-2026-34154 have on users?
CVE-2026-34154 allows unauthorized users to access subscription-gated groups without making the required payment.
Which plugin is affected by CVE-2026-34154?
CVE-2026-34154 affects the discourse-subscriptions plugin in Discourse.
When was CVE-2026-34154 published?
CVE-2026-34154 was published on May 19, 2026.