Improper access control in Discourse - CVE-2026-44786
Published: July 1, 2026
Discourse
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in public chat MessageBus broadcasts when publishing chat events for public category channels. A remote attacker can subscribe to MessageBus and receive chat message payloads in real time to disclose sensitive information.
The issue affects subscribers without chat enabled.