CVE-2026-31869Disclosure(discourse / discourse)

LOWCVSS 4.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the ComposerController#mentions endpoint reveals hidden group membership to any authenticated user who can message the group. By supplying allowed_names referencing a hidden-membership group and probing arbitrary usernames, an attacker can infer membership based on whether user_reasons returns "private" for a given user. This bypasses group member-visibility controls. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch. To work around this issue, restrict the messageable policy of any hidden-membership group to staff or group members only, so untrusted users cannot reach the vulnerable code path.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200CWE-285CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • discourse

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
discourse

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-20: 2Technical Details · 2026-03-20: 103-20
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-31869 Group Membership Disclosure Vulnerability in Discourse Prior to 2026.3.0-latest.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-31869

    Post summary

    A group membership disclosure vulnerability in Discourse (before 2026.3.0‑latest.1) is identified, but no further details on exploitation, patching, or PoC are included.

    0000049
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-31869 Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the ComposerController#mentions endpoint reveals hidden … https://www.cve.org/CVERecord?id=CVE-2026-31869

    Post summary

    The post announces CVE‑2026‑31869, noting a flaw in Discourse’s ComposerController#mentions endpoint on certain older releases, with a reference to the official CVE record.

    0000045
    56.8K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appdiscoursediscourse---
Appdiscoursediscourse2026.3.0--

Explore more