CVE-2026-44787Disclosure(discourse / discourse)

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the signup flow could allow newly registered users to set primary_group_id and gain whisper-group privileges without legitimate group membership on sites with whispers_allowed_groups configured. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • discourse

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 2 mentions (2026-07-10); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
discourse

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-07-10: 2Mentions · 2026-07-15: 1Mentions · 2026-08-07: 1Technical Details · 2026-07-10: 2Technical Details · 2026-07-15: 1Technical Details · 2026-08-07: 107-1007-1508-07
Signal classification1 categories
Disclosure
4100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-07-102
Disclosure2
2026-07-151
Disclosure1
2026-08-071
Disclosure1
Full discourse4 posts
  • Alp@alp0x01
    Disclosure

    1/4 🧵 🚨 CVE-2026-44787 (CVSS 7.2 High) Discourse trusted user-controlled primary_group_id during signup, enabling restricted-group self-assignment and employee impersonation. If whispers_allowed_groups matches, private whispers may also be exposed. https://t.co/BeF1n6DVA2

    Post summary

    The post announces CVE-2026-44787, a high‑score vulnerability in Discourse that allows users to manipulate primary group IDs during signup to impersonate employees and potentially expose private whispers.

    322821915.1K
    4.6K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Discourse, Improper Privilege Management, #CVE-2026-44787 (High) -DC-Jul2026-984 https://dailycve.com/discourse-improper-privilege-management-cve-2026-44787-high-dc-jul2026-984/

    Post summary

    The post announces CVE-2026-44787, an Improper Privilege Management flaw rated high, but provides no proof of concept, exploit code, or mitigation details.

    0000032
    219 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-44787 Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the signup flow could allow newly registered users to set primar… https://www.cve.org/CVERecord?id=CVE-2026-44787 ----- Traducción: CVE-2026-44787 Dis… http://infoflow.cloud`

    Post summary

    The text announces CVE-2026‑44787, a flaw in Discourse’s signup flow that lets new users set primary attributes, and links to the official CVE record for more details.

    0000042
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-44787 Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the signup flow could allow newly registered users to set primar… https://www.cve.org/CVERecord?id=CVE-2026-44787

    Post summary

    The post indicates a vulnerability in Discourse’s signup flow that could let new users elevate privileges on versions prior to 2026.6.0, but no proof of concept, exploit code, active exploitation, or patch details are provided.

    00000389
    57.8K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appdiscoursediscourse---
Appdiscoursediscourse2026.6.0--

Explore more