Junglewise Threat Intelligence

CVE-2026-45780: Discourse information disclosure in EventSerializer

CVE-2026-45780 · Severity: medium · CVSS 5.3 · Published 2026-07-09

Technologies: Discourse. Vendors: Discourse.

Executive brief

Discourse, a popular open-source discussion and community platform, contained a flaw that could leak private event information. Unauthorized users who were able to view a discussion topic could see sensitive details about private events, including invited group names, lists of attendees, and attendance statistics. This could lead to the exposure of private community interactions or member lists that were intended to remain confidential.

Technical details

An information disclosure vulnerability exists in the Discourse EventSerializer component within the discourse-calendar plugin. The root cause is a failure to properly gate private event invitee details during serialization, allowing unauthorized users with topic-view access to retrieve sensitive event metadata. An attacker can exploit this by viewing a topic containing a private event to obtain invited group names, sample invitee lists, and attendance statistics without having the required permissions to view the private invitee list. The issue has been addressed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5 by implementing proper permission checks in the serializer.

Affected products

  • Discourse Discourse < 2026.1.5, < 2026.4.2, < 2026.5.1, < 2026.6.0

Timeline

  • 2026-06-30: patched: Patched versions 2026.1.5, 2026.4.2, and 2026.5.1 released.
  • 2026-07-09: advisory: NVD and GitHub security advisory published.

References

Related threats