Junglewise Threat Intelligence

CVE-2026-32618: Discourse information disclosure in chat user search

CVE-2026-32618 · Severity: medium · CVSS 4.3 · Published 2026-03-31

Technologies: Discourse. Vendors: Discourse.

Executive brief

Discourse is an open-source platform used for hosting online community discussions and chat. A security flaw in the chat search feature allows users to determine who belongs to specific private chat channels without having the proper authorization. This could lead to the exposure of private group memberships or the identification of participants in restricted discussions.

Technical details

An information disclosure vulnerability (CWE-200) exists in Discourse's chat component due to insufficient authorization checks in the user search functionality. Specifically, the 'excluded_memberships_channel_id' parameter in the chat search service failed to verify if the requesting user had permission to preview or access the specified channel. By manipulating search queries, an authenticated attacker can infer whether specific users are members of private or restricted chat channels. The vulnerability is exploited via network requests to the chat API. Patches have been released in versions 2026.1.3, 2026.2.2, and 2026.3.0 which implement proper 'guardian' checks to ensure channel visibility before returning search results.

Affected products

  • Discourse Discourse 2026.1.0-latest to 2026.1.2, 2026.2.0-latest to 2026.2.1, 2026.3.0-latest before 2026.3.0

Timeline

  • 2026-03-31: advisory: Vendor advisory published via GitHub
  • 2026-03-31: patched: Fixes committed to main repository

References

Related threats