CVE-2026-27935General(discourse / discourse)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a vulnerability in an API endpoint that discloses private topic metadata of admin users to moderator users even if the moderators do not have access to the private topics. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch. No known workarounds are available.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-201

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • discourse

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-20); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
discourse

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-20: 2Mentions · 2026-03-24: 1Technical Details · 2026-03-24: 103-2003-24
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-202
Disclosure1General1
2026-03-241
General1
Full discourse3 posts
  • DailyCVE@dailycve
    General

    🟠 Discourse, Information Disclosure, #CVE-2026-27935 (Medium) https://dailycve.com/discourse-information-disclosure-cve-2026-27935-medium/

    Post summary

    The post notes CVE-2026-27935 as an information disclosure vulnerability of medium severity, but offers no details on exploitation, patches, or mitigation.

    0000027
    173 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-27935 Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a vulnerability in an API endpoint that discloses pr… https://www.cve.org/CVERecord?id=CVE-2026-27935 ----- Traducción: CVE-2026-27935 Dis… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑27935, identifies affected Discourse versions, and mentions a vague API‑endpoint disclosure issue, but provides no PoC, exploit details, patch information, or technical depth.

    0000039
    61 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-27935 Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a vulnerability in an API endpoint that discloses pr… https://www.cve.org/CVERecord?id=CVE-2026-27935

    Post summary

    The note announces that older Discourse versions contain an API data‑leak vulnerability, but it provides no details on exploitation, patch status, or technical specifics.

    00000182
    56.8K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appdiscoursediscourse---
Appdiscoursediscourse2026.3.0--

Explore more