---
id: CVE-2026-84302
title: Discourse is an open-source discussion platform
summary: >-
  Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2,
  2026.6.1, and 2026.7.0, Discourse AI reviewables associated with private
  messages could appear in the moderator review queue of a moderator who was not
  a parti…
severity: medium
cvss: 4.2
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N'
cwe:
  - CWE-862
vendor: discourse
product: discourse
affected:
  - discourse < 2026.7.0
  - 'discourse >= 2026.6.0-latest, < 2026.6.1'
  - 'discourse >= 2026.5.0-latest, < 2026.5.2'
  - 'discourse >= 2026.1.0-latest, < 2026.1.6'
published: '2026-09-24'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T18:19:03.923'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-84302'
references:
  - url: >-
      https://github.com/discourse/discourse/commit/1566d04524c01472375944bbf7b198dd09a99427
    label: security-advisories@github.com
  - url: >-
      https://github.com/discourse/discourse/commit/23488b72a200228e805c4e6d970fbad216d328c5
    label: security-advisories@github.com
  - url: >-
      https://github.com/discourse/discourse/commit/38d10c0e5d1b76540d2860455e0290f8e975c9fd
    label: security-advisories@github.com
  - url: >-
      https://github.com/discourse/discourse/commit/b323702d87cd82c327c116d9566477f3c4f9635f
    label: security-advisories@github.com
  - url: 'https://github.com/discourse/discourse/pull/42091'
    label: security-advisories@github.com
  - url: >-
      https://github.com/discourse/discourse/security/advisories/GHSA-3rx9-fqgh-wfpc
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-24T17:04:31.550424Z'
ingestedAt: '2026-09-24T17:48:30.385Z'
---

## Overview

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, Discourse AI reviewables associated with private messages could appear in the moderator review queue of a moderator who was not a participant in the message. Reviewable visibility filtering did not restrict private-message reviewables to the audience permitted to access the underlying private-message topic, allowing the moderator to read otherwise confidential content. Depending on the available reviewable action, the moderator could also modify the private message by closing its topic or deleting a post. Exploitation requires an authenticated moderator account and a pre-existing Discourse AI reviewable associated with a private message. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
