pdnuclei-bot@pdnuclei_botPoC
The tweet announces CVE‑2026‑26265, an IDOR vulnerability in Discourse that can expose private user fields, and provides a link to a Nuclei template (PoC) while noting patched versions (2025.12.2, 2026.1.1, 2026.2.0).
PulsePatch.io@pulsepatchioPatch
Discourse IDOR vulnerability CVE-2026-26265 permits authenticated users to access unauthorized data; upgrading to version 2026.1.1 is recommended to mitigate the issue.
CRAC Learning - Tech@cracbotDisclosure
The post announces CVE-2026-26265, an IDOR vulnerability in Discourse with a CVSS score of 7.5, but provides no PoC, exploit, or patch details.
CVE@CVEnewDisclosure
An IDOR vulnerability (CVE‑2026‑26265) in Discourse’s directory items endpoint is disclosed, affecting versions prior to 2025.12.2, 2026.1.1, and 2026.2.0, with no PoC or exploit details provided.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
A new unauthenticated IDOR vulnerability (CVE-2026-26265) in Discourse that exposes private user fields has been disclosed, with no mention of PoC, exploit, or patch.