Improper access control in Discourse - CVE-2026-33074
Published: July 1, 2026
Discourse
Detailed vulnerability description
The vulnerability allows a remote user to gain access to higher tier subscription benefits.
The vulnerability exists due to improper access control in the discourse-subscriptions plugin when processing subscription purchases. A remote user can purchase a lower tier subscription and grant themselves higher tier benefits to gain access to higher tier subscription benefits.