← Retour aux CVEs
CVE-2026-30891
N/ADescription
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a user could access another user's private activity due to insufficient authorization checks in the user actions endpoint. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch.
Details CVE
Score CVSS v3.1N/A
Publie3/20/2026
Derniere modification3/20/2026
Sourcenvd
Observations honeypot0
Faiblesses (CWE)
CWE-200
References
https://github.com/discourse/discourse/security/advisories/GHSA-ww5f-24g5-c33g(security-advisories@github.com)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.