Improper access control in Discourse - CVE-2026-59829
Published: July 29, 2026
Discourse
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the review queue when displaying flag-related private message excerpts and permalinks. A remote user can access the review queue to disclose sensitive information.
Only sites with category group moderation enabled are affected. The exposure is limited to excerpts and permalinks of notify_moderators flag messages, including cases involving core flags raised before a moderator's group was granted moderation of the category.