PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-32607 discourse CVE debrief

CVE-2026-32607 is a low-severity vulnerability in Discourse, an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, when the hidden prioritize_full_name_in_ux site setting is enabled (defaults to false, requires console access to change), user and group display names are rendered without HTML escaping in several assignment-related UI paths. This allows users with assign permission to inject arbitrary HTML/JavaScript that executes in the browser of any user viewing an affected topic. The vulnerability requires the prioritize_full_name_in_ux site setting to be enabled, which is not enabled by default. Users of Discourse, particularly those with assign permission, should be aware of this vulnerability and take steps to mitigate it.

Vendor
discourse
Product
Unknown
CVSS
LOW 2.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-31
Original CVE updated
2026-07-24
Advisory published
2026-03-31
Advisory updated
2026-07-24

Who should care

Users of Discourse, particularly those with assign permission, should be aware of this vulnerability and take steps to mitigate it. This vulnerability requires the prioritize_full_name_in_ux site setting to be enabled, which is not enabled by default. Affected operator, platform, vulnerability-management, and security-team impact should be reviewed.

Technical summary

The vulnerability exists in the Discourse platform, specifically in the rendering of user and group display names in assignment-related UI paths. When the prioritize_full_name_in_ux site setting is enabled, user and group display names are not properly HTML escaped, allowing for the injection of arbitrary HTML/JavaScript code. This code can be executed in the browser of any user viewing an affected topic, potentially leading to security issues. The vulnerability affects Discourse versions from 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0.

Defensive priority

Low

Recommended defensive actions

  • Update Discourse to version 2026.1.3, 2026.2.2, or 2026.3.0, or later
  • Disable the prioritize_full_name_in_ux site setting if not required
  • Monitor for suspicious activity on your Discourse instance
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record was published on 2026-03-31T18:16:50.060Z and was last modified on 2026-07-24T20:10:00.147Z. The NVD entry is currently Analyzed. This vulnerability affects Discourse users with assign permission and the prioritize_full_name_in_ux site setting enabled. Evidence is limited to CVE and NVD details.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-31T18:16:50.060Z and has not been modified since then. The NVD entry is currently Analyzed.