CVE-2026-28218Disclosure(discourse / discourse)

LOWCVSS 5.4 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, fail-open access control in Data Explorer plugin allows any authenticated user to execute SQL queries that have no explicit group assignments, including built-in system queries. Versions 2025.12.2, 2026.1.1, and 2026.2.0 patch the issue. As a workaround, either explicitly set group permissions on each Data Explorer query that doesn't have permissions, or disable discourse-data-explorer plugin.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • discourse

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
discourse

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-27: 2Technical Details · 2026-02-27: 202-27
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-28218 Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, fail-open access control in Data Explorer plugin allows any auth… https://www.cve.org/CVERecord?id=CVE-2026-28218

    Post summary

    The text announces a fail‑open access control vulnerability (CVE-2026-28218) in Discourse's Data Explorer plugin, affecting versions prior to 2025.12.2, 2026.1.1, and 2026.2.0.

    00000151
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28218 SQL Query Access Control Vulnerability in Discourse Data Explorer Plugin https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28218

    Post summary

    The post announces CVE-2026-28218 as an SQL query access control vulnerability in the Discourse Data Explorer Plugin, but provides only minimal technical details and no information on PoC, exploitation, or patch availability.

    0000037
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appdiscoursediscourse---
Appdiscoursediscourse2026.2.0--

Explore more