CVE-2026-44779: Discourse: Bot debug endpoints disclose whisper translation audit logs
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, bot debug endpoints disclose whisper translation audit logs. This issue has been patched in versions 2026.1.4, 2026.3.1, 2026.4.1, and 2026.5.0-latest.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Discourseto a version that resolves this vulnerability.Fixed in 2026.1.4 - Upgrade
Upgrade
Discourseto a version that resolves this vulnerability.Fixed in 2026.3.1 - Upgrade
Upgrade
Discourseto a version that resolves this vulnerability.Fixed in 2026.4.1 - Upgrade
Upgrade
Discourseto a version that resolves this vulnerability.Fixed in 2026.5.0-latest.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44779?
CVE-2026-44779 has a medium severity rating of 4.3.
How do I fix CVE-2026-44779?
To fix CVE-2026-44779, update Discourse to versions 2026.1.4, 2026.3.1, or 2026.4.1 or later.
What type of vulnerability is CVE-2026-44779?
CVE-2026-44779 is an information leak vulnerability affecting bot debug endpoints.
Which versions of Discourse are affected by CVE-2026-44779?
CVE-2026-44779 affects Discourse versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1.
What information is exposed in CVE-2026-44779?
CVE-2026-44779 discloses whisper translation audit logs through bot debug endpoints.