PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-33514 discourse CVE debrief

An authenticated information disclosure vulnerability exists in Discourse's form templates feature. Affected versions fail to enforce category-level authorization checks when retrieving form template metadata, allowing any authenticated user to read template names and structured content intended for restricted categories. The vulnerability requires the form templates feature to be enabled and valid user authentication. Impact is limited to configuration metadata disclosure without data modification capabilities.

Vendor
discourse
Product
Unknown
CVSS
MEDIUM 6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-19
Original CVE updated
2026-07-24
Advisory published
2026-05-19
Advisory updated
2026-07-24

Who should care

Discourse instance administrators, particularly those with multi-category deployments using form templates for structured data collection. Organizations with category-restricted templates containing sensitive field schemas or internal naming conventions.

Technical summary

The vulnerability exists in Discourse's form templates feature implementation where authorization checks for category-restricted templates are improperly enforced. Authenticated users can query template metadata across category boundaries, exposing template names and structured field definitions. The issue stems from missing authorization validation in template retrieval endpoints. Remediation involves upgrading to versions that implement proper category-scoped access controls for template metadata.

Defensive priority

medium

Recommended defensive actions

  • Upgrade Discourse to patched versions 2026.1.4, 2026.3.1, 2026.4.1, or 2026.5.0-latest.1
  • If immediate patching is not feasible, evaluate whether the form templates feature can be temporarily disabled
  • Review access logs for unusual template metadata access patterns by authenticated users
  • Verify category permission configurations are correctly enforced after patching

Evidence notes

Vulnerability confirmed via GitHub Security Advisory GHSA-w6g7-p2p9-2m5h with associated commit ae5c9570fb918442c4d96abc83c1e7e169909b02. CVSS 4.0 vector indicates network attack vector with low attack complexity, privileged access requirement, and high confidentiality impact to vulnerable component. CWE-862 (Missing Authorization) classified as primary weakness. NVD status 'Undergoing Analysis' as of 2026-05-19T14:44:04Z.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-33514 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-33514

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-33514 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-33514

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.