Junglewise Threat Intelligence

CVE-2026-44782: Discourse information disclosure in GroupPostSerializer

CVE-2026-44782 · Severity: medium · CVSS 4.3 · Published 2026-06-12

Technologies: Discourse. Vendors: Discourse.

Executive brief

Discourse, an open-source discussion platform, contains a flaw where users' full names are exposed even when the site is configured to hide them. This occurs because a technical error in the software's data-sharing component fails to check the privacy settings before sending user information. An authenticated user could potentially view the real names of other members who intended to remain anonymous, leading to a minor privacy breach.

Technical details

An information disclosure vulnerability exists in Discourse due to a naming mismatch in the Active Model Serializer (AMS) predicates within GroupPostSerializer. The serializer incorrectly declared 'include_user_long_name?' as the predicate for the ':name' attribute, whereas AMS expects 'include_name?'. Because the correct predicate was never invoked, the 'object.user.name' attribute was serialized in all responses, bypassing the 'SiteSetting.enable_names' privacy configuration. This allows authenticated users to view the full names of other users via API responses related to group posts, even when the platform is configured to keep names private. The issue is resolved by aligning the predicate naming in the patched versions.

Affected products

  • Discourse Discourse 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, 2026.4.0-latest to before 2026.4.1

Timeline

  • 2026-05-18: advisory: GitHub Security Advisory published
  • 2026-06-12: disclosed: NVD publication date

References

Related threats