Junglewise Threat Intelligence

CVE-2026-59829: Discourse information disclosure in category group moderation review queue

CVE-2026-59829 · Severity: medium · CVSS 4.3 · Published 2026-08-17

Technologies: Discourse. Vendors: Discourse.

Executive brief

Discourse, an open-source discussion platform, leaked private message excerpts in the moderation review queue to unauthorized category moderators. Moderators could view limited excerpts of flagged private messages they were not participants in and should not have access to, compromising the confidentiality of moderation discussions. The vulnerability is limited to information disclosure only—no data can be modified or deleted—and has been patched in recent versions.

Technical details

This vulnerability is an information disclosure flaw in Discourse's category group moderation system. When flags generate notify_moderators private messages, the review queue could include excerpts and permalinks of these messages even when the reviewing category moderator was not a participant and not part of the moderation group at the time the flag was raised. The root cause involves improper access control checks in the review queue display logic for flagged messages. Attack precondition: the site must have category group moderation enabled, and an attacker must have the role of category moderator. The impact is limited to reading restricted text excerpts; message content cannot be modified or deleted. Patches are available in Discourse versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.1.

Affected products

  • Discourse Discourse before 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.1

Timeline

  • 2026-08-17: disclosed
  • 2026: patched: Multiple patch versions released: 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.1

References

Related threats