Improper access control in Discourse - CVE-2022-46159

 

Improper access control in Discourse - CVE-2022-46159

Published: December 2, 2022 / Updated: July 1, 2026


Vulnerability identifier: #VU136076
CSH Severity: Low
CVSS v4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-46159
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to create an unlisted topic.

The vulnerability exists due to improper access control in topic creation functionality when handling requests to create topics. A remote user can submit a request to create an unlisted topic to create an unlisted topic.

These topics are not readily available to other users and can consume unnecessary site resources.


Affected software

Discourse

How to mitigate CVE-2022-46159

Install security update from vendor's website.

Discourse - addressed in versions 2.8.13, 2.9.0 beta14

External References

Related Security Bulletins