Junglewise Threat Intelligence

CVE-2026-44779: Discourse information disclosure in bot debug endpoints

CVE-2026-44779 · Severity: medium · CVSS 4.3 · Published 2026-06-12

Technologies: Discourse. Vendors: Discourse.

Executive brief

Discourse is an open-source platform used for hosting community discussion forums. A vulnerability in the platform's AI bot debugging features could allow certain users to view sensitive audit logs containing 'whisper' translations, which are intended to be private staff-only communications. This could lead to the unauthorized disclosure of internal discussions or confidential information shared within the forum's private moderation areas.

Technical details

An information disclosure vulnerability exists in Discourse's bot debug endpoints. The root cause is an improper authorization check that allows users with access to AI debug audit logs to view 'whisper' translation logs, which typically contain private staff-only messages. While the default configuration limits access to these logs, an attacker with low-level privileges could exploit this to read sensitive internal communications. The issue affects multiple 2026 release branches and has been addressed in versions 2026.1.4, 2026.3.1, 2026.4.1, and 2026.5.0-latest.1.

Affected products

  • Discourse Discourse 2026.1.0-latest to 2026.1.3, 2026.3.0-latest to 2026.3.0, 2026.4.0-latest to 2026.4.0

Timeline

  • 2026-05-18: advisory: GitHub Security Advisory published
  • 2026-06-12: disclosed: NVD publication date

References

Related threats