Junglewise Threat Intelligence

CVE-2026-72724: Discourse private chat message disclosure via onebox

CVE-2026-72724 · Severity: medium · CVSS 4.3 · Published 2026-08-10

Technologies: Discourse. Vendors: Discourse.

Executive brief

Discourse is an open-source community discussion platform. A flaw in the chat onebox handler allows an authenticated attacker to pair a public channel ID with a private thread ID to bypass access controls and view private chat messages they shouldn't be able to access. This could expose sensitive conversations and confidential information shared in private channels.

Technical details

The vulnerability is an access control bypass in plugins/chat/lib/chat/onebox_handler.rb. The vulnerable code resolves a Chat::Thread by route thread_id independently of the route channel_id before validating whether the user has permission to preview the target chat channel. An authenticated user can craft a /onebox.json request pairing a public channel ID with a private thread ID to bypass the authorization check. The attacker can then retrieve and view private thread message content. This affects versions prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0; patches are available in those versions.

Affected products

  • Discourse Discourse prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0

Timeline

  • 2026-08-10: disclosed
  • 2026-08-10: patched: Fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0

References

Related threats