Discourse CSV Export Admin Bypass 2026.1.0-2 / 2026.2.01
CVE-2026-32143 Published on March 31, 2026
Discourse: Admin-only report can be exported by moderators
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, moderators could export CSV data for admin-restricted reports, bypassing the report visibility restrictions. This could expose sensitive operational data intended only for admins. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.
Weakness Type
What is an Information Disclosure Vulnerability?
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVE-2026-32143 has been classified to as an Information Disclosure vulnerability or weakness.
Products Associated with CVE-2026-32143
Want to know whenever a new CVE is published for Discourse? stack.watch will email you.
Affected Versions
discourse:- Version >= 2026.1.0-latest, < 2026.1.3 is affected.
- Version >= 2026.2.0-latest, < 2026.2.2 is affected.
- Version >= 2026.3.0-latest, < 2026.3.0 is affected.