CVE-2026-33300: Discourse 2026.x Info Disclosure via Cat Chatables Ctrl
CVE-2026-33300 Published on March 31, 2026

Discourse: Hidden group names and access metadata are exposed to moderators through the `category-chatables` endpoint
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, an authorization bypass in the Category Chatables Controller show action allowed moderators to get information on hidden groups names and user count. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.

NVD

Weakness Type

What is an Information Disclosure Vulnerability?

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CVE-2026-33300 has been classified to as an Information Disclosure vulnerability or weakness.


Products Associated with CVE-2026-33300

Want to know whenever a new CVE is published for Discourse? stack.watch will email you.

 

Affected Versions

discourse: