Junglewise Threat Intelligence

CVE-2026-72723: Discourse information disclosure in anonymous navigation menu serialization

CVE-2026-72723 · Severity: medium · CVSS 5.3 · Published 2026-08-10

Technologies: Discourse. Vendors: Discourse.

Executive brief

Discourse is an open-source discussion platform used by communities to host forums and discussions. An unauthenticated attacker can retrieve the names and descriptions of restricted tags that should only be visible to authorized users, potentially exposing sensitive organizational or community information such as hidden categories or restricted discussion topics.

Technical details

The vulnerability exists in SiteSerializer.anonymous_default_navigation_menu_tags, which serializes tags from SiteSetting.default_navigation_menu_tags without properly filtering them through DiscourseTagging.filter_visible for anonymous viewers. An unauthenticated user can send a request to the /site.json endpoint to retrieve tag names and descriptions that should be restricted due to inaccessible categories, category tag groups, or tag-group permissions. The attacker does not need authentication or any special privileges; the information is exposed through a publicly accessible API endpoint. Patches are available in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.

Affected products

  • Discourse Discourse before 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0

Timeline

  • 2026-08-10: disclosed
  • 2026-08-10: patched: patches released in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0

References

Related threats