8.2

CVE-2026-44787

Discourse: Signup-time primary_group_id assignment grants whisperer access

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the signup flow could allow newly registered users to set primary_group_id and gain whisper-group privileges without legitimate group membership on sites with whispers_allowed_groups configured. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DiscourseDiscourse Version >= 2026.1.0 < 2026.1.5
DiscourseDiscourse Version >= 2026.4.0 < 2026.4.2
DiscourseDiscourse Version >= 2026.5.0 < 2026.5.1
DiscourseDiscourse Version2026.6.0 SwEditionlatest
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.27% 0.184
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.1 2.8 4.2
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
security-advisories@github.com 8.2 3.9 4.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

https://github.com/discourse/discourse/releases/tag/v2026.1.5
Release Notes
https://github.com/discourse/discourse/releases/tag/v2026.4.2
Release Notes
https://github.com/discourse/discourse/releases/tag/v2026.5.1
Release Notes
https://github.com/discourse/discourse/releases/tag/v2026.6.0
Release Notes
https://github.com/discourse/discourse/security/advisories/GHSA-vmwq-jvxx-jwfx
Vendor Advisory
Mitigation
https://github.com/discourse/discourse/commit/012796ac28c85b30aa233c5ef042fc66efff8126
Patch
https://github.com/discourse/discourse/commit/0f50a07a6ef4b33f3f826ce6d7bf6d7bd16912d8
Patch
https://github.com/discourse/discourse/commit/5418e3027dba109e27a4796463686d61e190ac29
Patch
https://github.com/discourse/discourse/commit/6fc7e6cf04422fc3f9d1c99134803071e983ff0a
Patch