PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-32619 discourse CVE debrief

CVE-2026-32619 is a medium-severity vulnerability affecting Discourse, an open-source discussion platform. The issue arises from versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0. In these versions, users who have lost access to a topic, such as being removed from a private category group, could still interact with polls within that topic. This includes voting and toggling poll status. Although no content was exposed, users could modify poll states in topics they should no longer have access to. The vulnerability has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.

Vendor
discourse
Product
Unknown
CVSS
MEDIUM 6.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-31
Original CVE updated
2026-07-24
Advisory published
2026-03-31
Advisory updated
2026-07-24

Who should care

Administrators and users of Discourse platforms should be aware of this vulnerability, especially those who manage private categories or groups. This issue could potentially allow unauthorized interactions with polls, leading to data integrity concerns.

Technical summary

The vulnerability exists due to improper access control in the poll feature of Discourse. Specifically, users who have lost access to a topic (e.g., removed from a private category group) can still interact with polls in that topic, including voting and changing poll status. This occurs in versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0. The CVSS score for this vulnerability is 6.3, classified as MEDIUM severity.

Defensive priority

Medium priority should be given to updating Discourse to the patched versions (2026.1.3, 2026.2.2, or 2026.3.0) to prevent unauthorized poll interactions.

Recommended defensive actions

  • Update Discourse to version 2026.1.3, 2026.2.2, or 2026.3.0, or later
  • Review and adjust access controls for private categories and groups
  • Monitor for any unauthorized changes to polls
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record was published on 2026-03-31T18:16:50.523Z and was last modified on 2026-07-24T20:10:00.147Z. The NVD entry is currently Analyzed. Evidence is limited to CVE and NVD information. Defenders should verify Discourse platform versions and update to patched versions if vulnerable. Review access controls for private categories and groups. Monitor for unauthorized changes to polls.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-31T18:16:50.523Z and has not been modified since then. The NVD entry is currently Analyzed.