Improper access control in Discourse - #VU140009
Published: July 29, 2026
Discourse
Detailed vulnerability description
The vulnerability allows a remote user to disclose restricted topic and private message titles.
The vulnerability exists due to improper access control in internal link extraction and duplicate lookup when processing canonicalized internal URLs. A remote user can submit or reference crafted internal URLs to disclose restricted topic and private message titles.