CVE-2026-26078Disclosure(discourse / discourse)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch discourse discourse systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, when the `patreon_webhook_secret` site setting is blank, an attacker can forge valid webhook signatures by computing an HMAC-MD5 with an empty string as the key. Since the request body is known to the sender, the attacker can produce a matching signature and send arbitrary webhook payloads. This allows unauthorized creation, modification, or deletion of Patreon pledge data and triggering patron-to-group synchronization. This vulnerability is patched in versions 2025.12.2, 2026.1.1, and 2026.2.0. The fix rejects webhook requests when the webhook secret is not configured, preventing signature forgery with an empty key. As a workaround, configure the `patreon_webhook_secret` site setting with a strong, non-empty secret value. When the secret is non-empty, an attacker cannot forge valid signatures without knowing the secret.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • discourse

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-03-03)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
discourse

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-26: 1Mentions · 2026-03-03: 2Patch / Workaround · 2026-03-03: 1Technical Details · 2026-02-26: 1Technical Details · 2026-03-03: 102-2603-03
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-261
Disclosure1
2026-03-032
General1Patch1
Full discourse3 posts
  • PulsePatch.io@pulsepatchio
    Patch

    A high-severity authentication bypass (CVE-2026-26078) affects the Discourse Patreon plugin webhook. Update to version 2026.1.1 to mitigate unauthorized access risk. #Discourse #InfoSec #Vulnerability https://www.pulsepatch.io/posts/cve-2026-26078-discourse-patreon-auth-bypass

    Post summary

    High‑severity authentication bypass in the Discourse Patreon plugin; updating to version 2026.1.1 is recommended to mitigate the risk.

    0000043
    1 followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-26078 (CVSS:7.5, HIGH) is Analyzed. Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, when the `patreon_..https://nvd.nist.gov/vuln/detail/CVE-2026-26078 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post references CVE-2026-26078 with a CVSS score of 7.5, noting affected Discourse versions but provides no details on exploitation, patches, or technical specifics.

    0000025
    173 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26078 Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, when the `patreon_webhook_secret` site setting is blank, an atta… https://www.cve.org/CVERecord?id=CVE-2026-26078

    Post summary

    CVE‑2026‑26078 is a vulnerability in Discourse that allows attackers to exploit a missing `patreon_webhook_secret` setting in older releases, potentially enabling unauthorized actions.

    00000102
    56.6K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appdiscoursediscourse---
Appdiscoursediscourse2026.2.0--

Explore more