
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21865 is a missing authorization vulnerability in Discourse, an open-source discussion platform, that allows moderators to convert private personal messages into public topics without proper authorization. Disclosed on January 28, 2026, it affects Discourse versions prior to 3.5.4 (stable), 2025.11.2, 2025.12.1, and 2026.1.0. It carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Red Hat CVE).
The root cause is CWE-862 (Missing Authorization) — the application fails to properly enforce access controls when moderators attempt to convert personal messages to public topics. Specifically, the topic conversion functionality does not verify whether the moderator has the necessary permissions to access the personal message being converted, allowing the action to proceed when it should be blocked. Exploitation requires an authenticated moderator account and is performed over the network with low attack complexity (GitHub Advisory).
Successful exploitation allows moderators to expose the contents of private personal messages by converting them into publicly visible topics, resulting in high confidentiality and integrity impact. Sensitive private communications between users — which may include personal, organizational, or confidential information — can be made accessible to all forum members or the public. There is no availability impact, and the scope is unchanged, meaning the vulnerability is contained to the Discourse instance itself (GitHub Advisory, Feedly).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.026% (0.000260), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a privileged moderator account, which significantly limits the attack surface (GitHub Advisory).
convert_topic or similar API calls) on personal message threads, particularly for messages they are not participants in.Discourse has released patched versions: 3.5.4 (stable), 2025.11.2, 2025.12.1, and 2026.1.0 — upgrading to any of these versions is the recommended remediation. As an interim workaround, site administrators can revoke the moderation role from untrusted moderators or remove the moderator group from the "personal message enabled groups" site setting until the instance is upgraded (GitHub Advisory).
The vulnerability was assigned a "Moderate" severity rating by the Discourse maintainer (davidtaylorhq) who published the GitHub Security Advisory on January 28, 2026. Coverage has been limited to vulnerability aggregator sites and security news feeds, with no notable independent researcher commentary or significant social media discussion identified (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."