Improper access control in Discourse - CVE-2026-34154
Published: July 1, 2026
Discourse
Detailed vulnerability description
The vulnerability allows a remote user to gain unauthorized access to subscription-gated groups.
The vulnerability exists due to improper access control in the discourse-subscriptions plugin when handling subscription-based group access. A remote user can obtain access to a subscription-gated group without completing payment to gain unauthorized access to subscription-gated groups.