216.73.217.22

CVE-2026-33251

· Published 20/03/2026 23:16 · Modified 20/03/2026 23:16

Labels: CVE-2026-33251 2026-03-20CVE-2026-33251CWE-863[email protected]

Essential information

Published
20/03/2026 23:16
Modified
20/03/2026 23:16
Author
Creator
CVSS
5.4 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

CVSS metrics

Description

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an authorization bypass vulnerability in hidden Solved topics may allow unauthorized users to accept or unaccept solutions. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch. As a workaround, ensure only trusted users are part of the Site Setting for accept_all_solutions_allowed_groups.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
discourse / discourse cpe:2.3:a:discourse:discourse:2026.1.2:*:*:*:*:*:*:*
discourse / discourse cpe:2.3:a:discourse:discourse:2026.2.1:*:*:*:*:*:*:*
discourse / discourse cpe:2.3:a:discourse:discourse:2026.3.0-latest.1:*:*:*:*:*:*:*

References