VYPR
Medium severity4.9NVD Advisory· Published Feb 26, 2026· Updated Jun 17, 2026

CVE-2026-27162

CVE-2026-27162

Description

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, posts_nearby was checking topic access but then returning all posts regardless of type, including whispers that should only be visible to whisperers. Use Post.secured(guardian) to properly filter post types based on user permissions. Versions 2025.12.2, 2026.1.1, and 2026.2.0 patch the issue. No known workarounds are available.

Affected products

5
  • cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*range: <2025.12.2
    • cpe:2.3:a:discourse:discourse:2026.2.0:*:*:*:latest:*:*:*
    • (no CPE)range: <2025.12.2, <2026.1.1, <2026.2.0
    • (no CPE)range: < 2025.12.2
  • osv-coords
    Range: < 2025.12.2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.