Improper access control in Discourse - CVE-2026-27934
Published: July 1, 2026
Discourse
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the user action API endpoint when handling requests for user actions. A remote attacker can request user action data to disclose sensitive information.
The issue may expose the title and post excerpt of private topics to unauthorized users.