Improper access control in Discourse - #VU140008

 

Improper access control in Discourse - #VU140008

Published: July 29, 2026


Vulnerability identifier: #VU140008
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: N/A
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available
Affected software:
Discourse

Detailed vulnerability description

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper access control in the SiteSerializer default navigation menu tag serialization when generating the anonymous site configuration response. A remote attacker can request the anonymous site configuration response to disclose sensitive information.

Tag names and descriptions restricted to inaccessible categories may be exposed.


Remediation

Install security update from vendor's website.

Sources