Improper access control in Discourse - CVE-2022-31025
Published: June 3, 2022 / Updated: July 1, 2026
Discourse
Detailed vulnerability description
The vulnerability allows a remote user to bypass user approval requirements.
The vulnerability exists due to improper access control in the invite approval logic when inviting users on sites that use single sign-on. A remote user can send an invite to bypass user approval requirements.
Only sites that use single sign-on are affected.