Improper access control in Discourse - CVE-2026-55704
Published: July 29, 2026
Discourse
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the group posts and group mentions endpoints when serializing group activity. A remote user can access those endpoints to disclose shared-draft topic titles and post excerpt/content.
Only users allowed to view a group's activity but not permitted to see shared drafts are able to access the leaked unpublished draft material.