Missing Authorization in Discourse - CVE-2026-27454
Published: July 1, 2026
Discourse
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to missing authorization in the posts endpoint when requesting /posts/:id.json with a version parameter. A remote attacker can enumerate version numbers to disclose sensitive information.
Hidden post revisions intended to be concealed by staff can be exposed.