Discourse CSV Export Admin Bypass 2026.1.0-2 / 2026.2.01
CVE-2026-32143 Published on March 31, 2026

Discourse: Admin-only report can be exported by moderators
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, moderators could export CSV data for admin-restricted reports, bypassing the report visibility restrictions. This could expose sensitive operational data intended only for admins. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.

NVD

Weakness Type

What is an Information Disclosure Vulnerability?

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CVE-2026-32143 has been classified to as an Information Disclosure vulnerability or weakness.


Products Associated with CVE-2026-32143

Want to know whenever a new CVE is published for Discourse? stack.watch will email you.

 

Affected Versions

discourse: