Improper access control in Discourse - #VU140002
Published: July 29, 2026
Discourse
Detailed vulnerability description
The vulnerability allows a remote user to disclose private chat thread messages.
The vulnerability exists due to improper access control in the onebox endpoint when handling onebox requests with a public chat channel ID paired with a private thread ID. A remote user can send a crafted onebox request to disclose private chat thread messages.