Improper access control in Discourse - #VU140008
Published: July 29, 2026
Discourse
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the SiteSerializer default navigation menu tag serialization when generating the anonymous site configuration response. A remote attacker can request the anonymous site configuration response to disclose sensitive information.
Tag names and descriptions restricted to inaccessible categories may be exposed.