---
id: CVE-2026-72726
title: Discourse is an open-source discussion platform
summary: >-
  Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2,
  2026.6.1, and 2026.7.0, an authenticated user could eavesdrop on private AI
  bot conversations through the AI bot reply stream. The issue is fixed in
  2026.1.6, …
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-200
published: '2026-08-10'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:54:37.790'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-72726'
references:
  - url: >-
      https://github.com/discourse/discourse/commit/01faa889830f56e02fba2f6c1731811d319c5e81
    label: security-advisories@github.com
  - url: >-
      https://github.com/discourse/discourse/commit/1fb2026eb8004dfeb12553014cc534dfd8083fbc
    label: security-advisories@github.com
  - url: >-
      https://github.com/discourse/discourse/commit/9247666f8359f3cf214b8aea3d396e8a8237ed38
    label: security-advisories@github.com
  - url: >-
      https://github.com/discourse/discourse/commit/b56b98232aa4dad4a30500a65e31db0c9080c8f5
    label: security-advisories@github.com
  - url: >-
      https://github.com/discourse/discourse/security/advisories/GHSA-gw88-2jw8-jf2h
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00452
epssPercentile: 0.36681
ingestedAt: '2026-09-08T21:11:12.273Z'
---

## Overview

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an authenticated user could eavesdrop on private AI bot conversations through the AI bot reply stream. The issue is fixed in 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
