6.5
CVE-2026-46413
- EPSS 0.37%
- Veröffentlicht 09.07.2026 21:55:45
- Zuletzt bearbeitet 14.07.2026 20:41:29
- CVE-Watchlists
- Unerledigt
Discourse: Regular users can route multipart uploads into the admin backup store
Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, regular users could route direct S3 multipart uploads through ExternalUploadManager into the admin backup store. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.37% | 0.287 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
https://github.com/discourse/discourse/releases/tag/v2026.1.5
https://github.com/discourse/discourse/releases/tag/v2026.4.2
https://github.com/discourse/discourse/releases/tag/v2026.5.1
https://github.com/discourse/discourse/releases/tag/v2026.6.0
https://github.com/discourse/discourse/security/advisories/GHSA-3mvf-q9rg-w6m7
https://github.com/discourse/discourse/commit/1f1ded8dd361d81786bff17b35e1138d6ee299c0
https://github.com/discourse/discourse/commit/7ddde266617b452152c1bf5f903f6c07be38fc40
https://github.com/discourse/discourse/commit/a53df26dcf7e50ce2b20bfd5454a0c9d44b8fc7d
https://github.com/discourse/discourse/commit/abaa664c5df84026efb2ca264ba0f5586c3f2b01