TROYANOSYVIRUS
Back to CVEs

CVE-2026-27150

LOW
3.8

Description

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, missing `validate_before_create` authorization in Data Explorer's `QueryGroupBookmarkable` allows any logged-in user to create bookmarks for query groups they don't have access to, enabling metadata disclosure via bookmark reminder notifications. Versions 2025.12.2, 2026.1.1, and 2026.2.0 fix this issue and also make sure `validate_before_create` throws NotImplementedError in BaseBookmarkable if not implemented, to prevent similar issues in the future. No known workarounds are available.

CVE Details

CVSS v3.1 Score3.8
SeverityLOW
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredHIGH
User InteractionNONE
Published2/26/2026
Last Modified3/2/2026
Sourcenvd
Honeypot Sightings0

Affected Products

discourse:discourse

Weaknesses (CWE)

CWE-862

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.