Improper access control in Discourse - CVE-2026-45085
Published: July 1, 2026
Discourse
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the chat plugin and discourse-calendar integration when rendering calendar event payloads and flagged chat message review content. A remote attacker can access crafted or affected content to disclose sensitive information.
Affects sites with the chat plugin enabled; the calendar-related exposure additionally requires discourse-calendar, and anonymous users may be able to view exposed chat channel details and the last message without chat access.