CVE-2026-45780: Discourse: Private event sample invitees are serialized to non-invited event viewers
Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, EventSerializer could expose invited group names, sample invitees, and attendance statistics to users who could view the topic but were not entitled to view the private event invitee list. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2026.6.0 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2026.5.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2026.4.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2026.1.5
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45780?
The severity of CVE-2026-45780 is medium with a CVSS score of 5.3.
How do I fix CVE-2026-45780?
To fix CVE-2026-45780, upgrade Discourse to version 2026.6.0, 2026.5.1, 2026.4.2, or 2026.1.5.
What does CVE-2026-45780 affect?
CVE-2026-45780 affects the Discourse open-source discussion platform.
What type of vulnerability is CVE-2026-45780?
CVE-2026-45780 is categorized as an information leak vulnerability.
What can be exposed by CVE-2026-45780?
CVE-2026-45780 can expose invited group names, sample invitees, and attendance statistics to unauthorized users.