Improper access control in Discourse - CVE-2025-64528
Published: July 1, 2026
Discourse
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in user search functionality when querying for users by name via the UI or API. A remote attacker can search using a partial user name to disclose sensitive information.
The issue occurs even when the enable_names setting is disabled.