CVE-2026-32244
Description
Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, outdated cached AI summaries can leak removed content to anonymous and unprivileged users who cannot regenerate summaries. This issue has been fixed in versions 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1. To work around this issue, restrict summary generation by tightening the allowed groups on the summarization Personas.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Discourse cached AI summaries can expose removed content to unauthorized users if not regenerated.
Vulnerability
In Discourse versions prior to 2026.1.4, 2026.3.1, 2026.4.1, and 2026.5.0-latest.1, AI-generated summaries that are cached may continue to display content that has been removed from the underlying topic or post. This occurs because the cached summary is not automatically invalidated or regenerated when the source content is deleted or edited, leading to a discrepancy between the visible summary and the actual content [1].
Exploitation
An anonymous or unprivileged user who can view a topic (but lacks permission to see or regenerate summaries) can read the cached AI summary that may contain the removed content. No authentication is required beyond what is needed to view the topic, and no user interaction from the victim is necessary. The attack complexity is low, and the attack vector is network-based, allowing remote exploitation [1].
Impact
Successful exploitation results in unauthorized disclosure of information that was intended to be deleted or hidden. This confidentiality breach can expose sensitive discussions or data that the application administrators believed were no longer accessible. The integrity or availability of the system is not directly affected [1].
Mitigation
The issue has been fixed in Discourse versions 2026.1.4, 2026.3.1, 2026.4.1, and 2026.5.0-latest.1. Administrators can work around the vulnerability by restricting which groups are allowed to generate summaries via the summarization Personas feature, thus limiting the number of users who might encounter outdated cached summaries [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2<2026.1.4 || <2026.3.1 || <2026.4.1 || <2026.5.0-latest.1+ 1 more
- (no CPE)range: <2026.1.4 || <2026.3.1 || <2026.4.1 || <2026.5.0-latest.1
- (no CPE)range: < 2026.1.4 || 2026.3.1 || 2026.4.1 || 2026.5.0-latest.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
3- Pro-Iran crew turns DDoS into shakedown as Ubuntu.com stays downThe Register Security · May 1, 2026
- Pro-Iran crew turns DDoS into shakedown as Ubuntu.com stays downThe Register Security · May 1, 2026
- Can AI Attack the Cloud? Lessons From Building an Autonomous Cloud Offensive Multi-Agent SystemUnit 42 · Apr 23, 2026