CVE-2026-26265Disclosure(discourse / discourse)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch discourse discourse systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, an IDOR vulnerability in the directory items endpoint allows any user, including anonymous users, to retrieve private user field values for all users in the directory. The `user_field_ids` parameter in `DirectoryItemsController#index` accepts arbitrary user field IDs without authorization checks, bypassing the visibility restrictions (`show_on_profile` / `show_on_user_card`) that are enforced elsewhere (e.g., `UserCardSerializer` via `Guardian#allowed_user_field_ids`). An attacker can request `GET /directory_items.json?period=all&user_field_ids=<id>` with any private field ID and receive that field's value for every user in the directory response. This enables bulk exfiltration of private user data such as phone numbers, addresses, or other sensitive custom fields that admins have explicitly configured as non-public. The issue is patched in versions 2025.12.2, 2026.1.1, and 2026.2.0 by filtering `user_field_ids` against `UserField.public_fields` for non-staff users before building the custom field map. As a workaround, site administrators can remove sensitive data from private user fields, or disable the user directory via the `enable_user_directory` site setting.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863CWE-639

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • discourse

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-02-26); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
discourse

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-02-26: 2Mentions · 2026-03-03: 2Mentions · 2026-09-14: 1PoC Mentioned / Linked · 2026-09-14: 1Patch / Workaround · 2026-02-26: 1Patch / Workaround · 2026-03-03: 1Patch / Workaround · 2026-09-14: 1Technical Details · 2026-02-26: 2Technical Details · 2026-03-03: 2Technical Details · 2026-09-14: 102-2603-0309-14
Signal classification3 categories
Disclosure
360.0%
Patch
120.0%
PoC
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-262
Disclosure2
2026-03-032
Disclosure1Patch1
2026-09-141
PoC1
Full discourse5 posts
  • pdnuclei-bot@pdnuclei_bot
    PoC

    🚨 CVE-2026-26265 - high 🚨 Discourse - Private User Field Disclosure via Directory Items IDOR &gt; Discourse prior to 2025.12.2, 2026.1.1, and 2026.2.0 contains an IDOR vulnerability c... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-26265 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces CVE‑2026‑26265, an IDOR vulnerability in Discourse that can expose private user fields, and provides a link to a Nuclei template (PoC) while noting patched versions (2025.12.2, 2026.1.1, 2026.2.0).

    00052425
    1.3K followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    An IDOR vulnerability (CVE-2026-26265) in `Discourse` affects the directory items endpoint, allowing authenticated users potential unauthorized data access. Upgrade to version 2026.1.1. #Discourse #infosec #IDOR https://www.pulsepatch.io/posts/cve-2026-26265-discourse-idor-vulnerability

    Post summary

    Discourse IDOR vulnerability CVE-2026-26265 permits authenticated users to access unauthorized data; upgrading to version 2026.1.1 is recommended to mitigate the issue.

    1000097
    1 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-26265 (CVSS:7.5, HIGH) is Analyzed. Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, an IDOR vulnerabil..https://nvd.nist.gov/vuln/detail/CVE-2026-26265 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-26265, an IDOR vulnerability in Discourse with a CVSS score of 7.5, but provides no PoC, exploit, or patch details.

    0001028
    173 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26265 Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, an IDOR vulnerability in the directory items endpoint allows any… https://www.cve.org/CVERecord?id=CVE-2026-26265

    Post summary

    An IDOR vulnerability (CVE‑2026‑26265) in Discourse’s directory items endpoint is disclosed, affecting versions prior to 2025.12.2, 2026.1.1, and 2026.2.0, with no PoC or exploit details provided.

    00000103
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-26265 Unauthenticated IDOR Vulnerability in Discourse Exposing Private User Fields https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-26265

    Post summary

    A new unauthenticated IDOR vulnerability (CVE-2026-26265) in Discourse that exposes private user fields has been disclosed, with no mention of PoC, exploit, or patch.

    0000038
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appdiscoursediscourse---
Appdiscoursediscourse2026.2.0--

Explore more