Executive brief
Discourse is an open-source platform used for hosting online discussion forums and communities. A security flaw allows unauthorized individuals to view 'staff-only' tags and their associated data, which are intended to be hidden from the public. This could lead to the exposure of internal organizational labels or sensitive metadata used by forum moderators.
Technical details
An authorization bypass vulnerability exists in Discourse's tag routes. The flaw allows unauthenticated or unauthorized actors to circumvent access controls intended to restrict 'staff-only' tag groups. By accessing specific tag-related routes, an attacker can view hidden tags and metadata associated with them. The issue affects instances where tagging is enabled and staff-only tag groups are configured. Patches are available in versions 2026.1.3, 2026.2.2, and 2026.3.0.
Affected products
- Discourse Discourse 2026.1.0-latest to < 2026.1.3, 2026.2.0-latest to < 2026.2.2, 2026.3.0-latest to < 2026.3.0
Timeline
- 2026-03-31: advisory: GitHub Security Advisory published by maintainers.
- 2026-04-03: disclosed: CVE published to NVD.
- 2026-04-03: patched: Fixes released in versions 2026.1.3, 2026.2.2, and 2026.3.0.