CVE-2026-33425
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, unauthenti
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, unauthenticated users can determine whether a specific user is a member of a private group by observing changes in directory results when using the exclude_groups parameter. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch.
As a workaround, disable public access to the user directory via Admin - Settings - hide user profiles from public.
MEDIUM · CVSS 5.3
EPSS 0.00076
Monitor
- No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence
Sigma rules0
YARA rules0