Executive brief
Discourse, a popular open-source discussion and community platform, contained a flaw in its user registration process. An attacker could exploit this during signup to grant themselves unauthorized access to "whisper" groups, which are typically reserved for staff or moderators to discuss sensitive information privately. This could lead to the exposure of confidential internal discussions and community management data.
Technical details
An improper privilege management vulnerability (CWE-269) exists in the Discourse signup flow. The root cause is the ability for newly registering users to manipulate the 'primary_group_id' parameter during the account creation process. On sites where 'whispers_allowed_groups' is configured, an attacker can assign themselves to a privileged group, thereby gaining access to "whisper" (private staff-only) threads without legitimate authorization. This is a remote, unauthenticated attack vector requiring no user interaction. The issue has been patched in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5.
Affected products
- Discourse Discourse < 2026.1.5, < 2026.4.2, < 2026.5.1, < 2026.6.0
Timeline
- 2026-07-09: advisory: NVD publication date
- 2026-06-30: patched: Release tags for fixed versions created on GitHub
References
- https://github.com/discourse/discourse/commit/012796ac28c85b30aa233c5ef042fc66efff8126
- https://github.com/discourse/discourse/commit/0f50a07a6ef4b33f3f826ce6d7bf6d7bd16912d8
- https://github.com/discourse/discourse/commit/5418e3027dba109e27a4796463686d61e190ac29
- https://github.com/discourse/discourse/commit/6fc7e6cf04422fc3f9d1c99134803071e983ff0a
- https://github.com/discourse/discourse/releases/tag/v2026.1.5
- https://github.com/discourse/discourse/releases/tag/v2026.4.2
- https://github.com/discourse/discourse/releases/tag/v2026.5.1