Executive brief
Discourse is an open-source platform used for hosting online discussion forums and communities. A vulnerability in its subscription plugin allows users to bypass payment requirements to join private, subscription-only groups. This could lead to a loss of revenue and unauthorized access to restricted community content.
Technical details
A missing authorization vulnerability (CWE-862) exists in the discourse-subscriptions plugin for the Discourse discussion platform. The flaw allows a remote attacker to bypass the intended payment workflow and gain membership to restricted groups that should require a paid subscription. Exploitation requires specific conditions (Attack Requirements: Present) and user interaction, resulting in a low-impact breach of confidentiality regarding restricted group content. The issue is resolved in versions 2026.1.4, 2026.3.1, 2026.4.1, and 2026.5.0-latest.1.
Affected products
- Discourse Discourse < 2026.1.4, < 2026.3.1, < 2026.4.1, < 2026.5.0-latest.1
Timeline
- 2026-05-18: advisory: GitHub Security Advisory published by Discourse
- 2026-05-19: disclosed: CVE published to NVD