Discourse Private Activity Exposure via Insufficient Auth Checks (pre-2026.3.0-latest.1)
CVE-2026-30891 Published on March 20, 2026
Discourse hasUnauthorized Exposure of Private User Action Types
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a user could access another user's private activity due to insufficient authorization checks in the user actions endpoint. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch.
Weakness Type
What is an Information Disclosure Vulnerability?
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVE-2026-30891 has been classified to as an Information Disclosure vulnerability or weakness.
Products Associated with CVE-2026-30891
Want to know whenever a new CVE is published for Discourse? stack.watch will email you.
Affected Versions
discourse:- Version >= 2026.1.0-latest, < 2026.1.2 is affected.
- Version >= 2026.2.0-latest, < 2026.2.1 is affected.
- Version = 2026.3.0-latest.1 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.