Junglewise Threat Intelligence

CVE-2026-34947: Discourse information disclosure in public invite pages

CVE-2026-34947 · Severity: medium · CVSS 5.3 · Published 2026-04-03

Technologies: Discourse. Vendors: Discourse.

Executive brief

Discourse is an open-source platform used for hosting online discussion forums and communities. A security flaw allowed sensitive information, including usernames and custom profile data, to be visible on public invitation pages before a user's email address was verified. This could lead to the unauthorized exposure of private user details to anyone on the internet.

Technical details

An information disclosure vulnerability exists in Discourse due to improper access control on public invite pages. The application fails to verify email ownership before displaying 'staged' user data, which includes usernames and custom profile fields. An unauthenticated remote attacker can access these public invite pages to harvest sensitive user information. The issue affects versions 2026.1.0-latest through 2026.1.2, 2026.2.0-latest through 2026.2.1, and 2026.3.0-latest. Patches are available in versions 2026.1.3, 2026.2.2, and 2026.3.0.

Affected products

  • Discourse Discourse 2026.1.0-latest to 2026.1.2, 2026.2.0-latest to 2026.2.1, 2026.3.0-latest before 2026.3.0

Timeline

  • 2026-03-31: advisory: GitHub Security Advisory published
  • 2026-04-03: disclosed: NVD publication date

References

Related threats