Junglewise Threat Intelligence

CVE-2026-34154: Discourse discourse-subscriptions authorization bypass in gated groups

CVE-2026-34154 · Severity: info · CVSS 2.1 · Published 2026-05-19

Technologies: Discourse. Vendors: Discourse.

Executive brief

Discourse is an open-source platform used for hosting online discussion forums and communities. A vulnerability in its subscription plugin allows users to bypass payment requirements to join private, subscription-only groups. This could lead to a loss of revenue and unauthorized access to restricted community content.

Technical details

A missing authorization vulnerability (CWE-862) exists in the discourse-subscriptions plugin for the Discourse discussion platform. The flaw allows a remote attacker to bypass the intended payment workflow and gain membership to restricted groups that should require a paid subscription. Exploitation requires specific conditions (Attack Requirements: Present) and user interaction, resulting in a low-impact breach of confidentiality regarding restricted group content. The issue is resolved in versions 2026.1.4, 2026.3.1, 2026.4.1, and 2026.5.0-latest.1.

Affected products

  • Discourse Discourse < 2026.1.4, < 2026.3.1, < 2026.4.1, < 2026.5.0-latest.1

Timeline

  • 2026-05-18: advisory: GitHub Security Advisory published by Discourse
  • 2026-05-19: disclosed: CVE published to NVD

References

Related threats