{"id":"CVE-2026-44787","title":"Discourse is an open-source discussion platform","summary":"Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the signup flow could allow newly registered users to set primary_group_id and gain whisper-group privileges without legitimate group m…","severity":"high","cvss":8.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N","cwe":["CWE-269"],"published":"2026-07-09","updated":"2026-07-10","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-44787","references":[{"url":"https://github.com/discourse/discourse/commit/012796ac28c85b30aa233c5ef042fc66efff8126","label":"security-advisories@github.com"},{"url":"https://github.com/discourse/discourse/commit/0f50a07a6ef4b33f3f826ce6d7bf6d7bd16912d8","label":"security-advisories@github.com"},{"url":"https://github.com/discourse/discourse/commit/5418e3027dba109e27a4796463686d61e190ac29","label":"security-advisories@github.com"},{"url":"https://github.com/discourse/discourse/commit/6fc7e6cf04422fc3f9d1c99134803071e983ff0a","label":"security-advisories@github.com"},{"url":"https://github.com/discourse/discourse/releases/tag/v2026.1.5","label":"security-advisories@github.com"},{"url":"https://github.com/discourse/discourse/releases/tag/v2026.4.2","label":"security-advisories@github.com"},{"url":"https://github.com/discourse/discourse/releases/tag/v2026.5.1","label":"security-advisories@github.com"},{"url":"https://github.com/discourse/discourse/releases/tag/v2026.6.0","label":"security-advisories@github.com"},{"url":"https://github.com/discourse/discourse/security/advisories/GHSA-vmwq-jvxx-jwfx","label":"security-advisories@github.com"}],"tags":["nvd"],"epss":0.00461,"epssPercentile":0.39236,"ingestedAt":"2026-07-11T20:15:25.743Z","slug":"CVE-2026-44787","body":"## Overview\n\nDiscourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the signup flow could allow newly registered users to set primary_group_id and gain whisper-group privileges without legitimate group membership on sites with whispers_allowed_groups configured. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":45.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}