
Discourse Data Explorer CVE-2026-72731 can let permitted query users read arbitrary database tables through crafted parameters. Patch to a fixed branch; until then, disable the plugin or limit it to trusted users. https://github.com/discourse/discourse/security/advisories/GHSA-wm63-83xp-59r5
Post summary
The advisory highlights CVE-2026-72731, which permits unauthorized database table reads via crafted parameters, and recommends using a patch, disabling the plugin, or restricting usage to trusted users.
