Junglewise Threat Intelligence

CVE-2026-46413: Discourse missing authorization in ExternalUploadManager S3 uploads

CVE-2026-46413 · Severity: medium · CVSS 6.5 · Published 2026-07-09

Technologies: Discourse. Vendors: Discourse.

Executive brief

Discourse, a popular open-source discussion and community platform, was found to have a security flaw in how it handles file uploads. This vulnerability allowed standard users to bypass intended restrictions and upload files directly into the administrative backup storage area. While this does not directly expose data, it could allow unauthorized users to interfere with system backups or consume administrative storage space.

Technical details

A missing authorization vulnerability (CWE-862) in Discourse allowed authenticated regular users to misdirect S3 multipart uploads. By leveraging the ExternalUploadManager, an attacker could route these uploads into the restricted admin backup store rather than the intended public or user-specific upload directories. The attack is reachable over the network and requires low-privileged user authentication. This could lead to unauthorized modification or cluttering of the backup storage backend. The issue has been addressed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5 by implementing stricter routing checks for multipart uploads.

Affected products

  • Discourse Discourse < 2026.1.5, < 2026.4.2, < 2026.5.1, < 2026.6.0

Timeline

  • 2026-06-30: patched: Patched versions 2026.1.5, 2026.4.2, and 2026.5.1 released.
  • 2026-07-09: advisory: NVD and GitHub Security Advisory published.

References

Related threats