PatchSiren cyber security CVE debrief
CVE-2026-32951 discourse CVE debrief
CVE-2026-32951 is an information disclosure vulnerability affecting Discourse, an open-source discussion platform. The issue allows an authenticated user to obtain shared draft topic titles by sending an inline onebox request with a category_id parameter matching the shared drafts category. This vulnerability exists in versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0. The vulnerability has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0. The debrief provides an executive overview of the vulnerability, including the exposure question, likely defender workflow, and priority posture.
- Vendor
- discourse
- Product
- Unknown
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-31
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-03-31
- Advisory updated
- 2026-07-24
Who should care
Users of Discourse, particularly those with shared drafts, should be aware of this vulnerability and take steps to protect themselves. This includes updating to a patched version of Discourse and monitoring for potential exploitation attempts. Affected operators, platform administrators, vulnerability management teams, and security teams should prioritize patching this vulnerability.
Technical summary
The vulnerability exists due to improper handling of inline onebox requests with a category_id parameter matching the shared drafts category in Discourse, an open-source discussion platform. This allows an authenticated user to obtain shared draft topic titles. The issue affects versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0. The vulnerability has a CVSS score of 4.3 and a severity of MEDIUM. The technical impact is that an authenticated user can access sensitive information, specifically shared draft topic titles.
Defensive priority
Medium priority should be given to patching this vulnerability, as it allows for information disclosure and could potentially be used by attackers to gather sensitive information.
Recommended defensive actions
- Update to a patched version of Discourse (2026.1.3, 2026.2.2, or 2026.3.0)
- Monitor for potential exploitation attempts
- Review and adjust category_id parameters for shared drafts
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record was published on 2026-03-31T18:16:51.530Z and was last modified on 2026-07-24T20:10:00.147Z. The NVD entry is currently Analyzed. The evidence is limited, and defenders should verify the affected scope and severity with the vendor. The CVE details are based on the NVD entry and the official CVE record.
Official resources
-
CVE-2026-32951 CVE record
CVE.org
-
CVE-2026-32951 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Patch
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-31T18:16:51.530Z and has not been modified since then. The NVD entry is currently Analyzed.