← Back

CVE-2026-32099

nvd nist
Published: Mar 19, 2026Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, when a user has `hide_profile` enabled, their bio, location, and website were still exposed through the user onebox preview. An authenticated user could request a onebox for a hidden user's profile URL and receive their hidden profile fields (bio, location, website) in the response. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch. No known workarounds are available.

Affected (3)

Products: Discourse: Discourse
1 product
Discourse
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Discourse
From 2026.1.0 to 2026.1.2
From 2026.2.0 to 2026.2.1
Version 2026.3.0

References (1)

Source: security-advisories@github.com
Vendor Advisory

Timeline

No history available yet.