PatchSiren cyber security CVE debrief
CVE-2026-32607 discourse CVE debrief
CVE-2026-32607 is a low-severity vulnerability in Discourse, an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, when the hidden prioritize_full_name_in_ux site setting is enabled (defaults to false, requires console access to change), user and group display names are rendered without HTML escaping in several assignment-related UI paths. This allows users with assign permission to inject arbitrary HTML/JavaScript that executes in the browser of any user viewing an affected topic. The vulnerability requires the prioritize_full_name_in_ux site setting to be enabled, which is not enabled by default. Users of Discourse, particularly those with assign permission, should be aware of this vulnerability and take steps to mitigate it.
- Vendor
- discourse
- Product
- Unknown
- CVSS
- LOW 2.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-31
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-03-31
- Advisory updated
- 2026-07-24
Who should care
Users of Discourse, particularly those with assign permission, should be aware of this vulnerability and take steps to mitigate it. This vulnerability requires the prioritize_full_name_in_ux site setting to be enabled, which is not enabled by default. Affected operator, platform, vulnerability-management, and security-team impact should be reviewed.
Technical summary
The vulnerability exists in the Discourse platform, specifically in the rendering of user and group display names in assignment-related UI paths. When the prioritize_full_name_in_ux site setting is enabled, user and group display names are not properly HTML escaped, allowing for the injection of arbitrary HTML/JavaScript code. This code can be executed in the browser of any user viewing an affected topic, potentially leading to security issues. The vulnerability affects Discourse versions from 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0.
Defensive priority
Low
Recommended defensive actions
- Update Discourse to version 2026.1.3, 2026.2.2, or 2026.3.0, or later
- Disable the prioritize_full_name_in_ux site setting if not required
- Monitor for suspicious activity on your Discourse instance
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record was published on 2026-03-31T18:16:50.060Z and was last modified on 2026-07-24T20:10:00.147Z. The NVD entry is currently Analyzed. This vulnerability affects Discourse users with assign permission and the prioritize_full_name_in_ux site setting enabled. Evidence is limited to CVE and NVD details.
Official resources
-
CVE-2026-32607 CVE record
CVE.org
-
CVE-2026-32607 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Patch
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-31T18:16:50.060Z and has not been modified since then. The NVD entry is currently Analyzed.