
1/4 🧵 🚨 CVE-2026-44787 (CVSS 7.2 High) Discourse trusted user-controlled primary_group_id during signup, enabling restricted-group self-assignment and employee impersonation. If whispers_allowed_groups matches, private whispers may also be exposed. https://t.co/BeF1n6DVA2
Post summary
The post announces CVE-2026-44787, a high‑score vulnerability in Discourse that allows users to manipulate primary group IDs during signup to impersonate employees and potentially expose private whispers.



