Junglewise Threat Intelligence

CVE-2026-72726: Discourse AI bot reply stream information disclosure

CVE-2026-72726 · Severity: medium · CVSS 6.5 · Published 2026-08-10

Technologies: Discourse. Vendors: Discourse.

Executive brief

Discourse is an open-source discussion platform that includes AI bot features. An authenticated user could eavesdrop on private AI bot conversations through the reply stream mechanism, potentially exposing sensitive discussions between other users and AI bots. This allows unauthorized access to private conversation content.

Technical details

This vulnerability is an authorization/access control issue in the AI bot reply streaming functionality. Authenticated users could access private messages (PMs) containing AI bot replies even when they were not participants in those conversations. The root cause was insufficient scoping of the reply stream to only include PM participants. The fix, implemented in the patched versions, restricts the reply stream visibility by scoping it to the private message's actual participants through stream_user_ids and stream_group_ids variables. No authentication bypass is required—the attacker must be an authenticated user, but network access is sufficient for exploitation.

Affected products

  • Discourse Discourse Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0

Timeline

  • 2026-08-10: disclosed
  • 2026-07-28: patched: Security fixes committed to repository

References

Related threats