
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28219 is a privilege escalation vulnerability in Discourse, an open-source discussion platform, caused by an improper authorization check in the topic management logic. It allows authenticated users to elevate their topics to site-wide notices or banners — a capability restricted to administrators — by manipulating parameters in PUT or POST requests. Affected versions include all releases prior to 2025.12.2 and 2026.1.0 prior to 2026.1.1; patched versions are 2025.12.2, 2026.1.1, and 2026.2.0. The vulnerability was published on February 26, 2026, with a patch released on March 2, 2026. It carries a CVSS v3.1 base score of 4.3 (Medium) and a CVSS v4.0 base score of 1.3 (Low) (GitHub Advisory, Red Hat CVE).
The root cause is classified as CWE-915 (Improperly Controlled Modification of Dynamically-Determined Object Attributes), commonly known as a mass assignment vulnerability. The topic management logic in Discourse fails to restrict which object attributes an authenticated user can modify when submitting PUT or POST requests, allowing privileged fields — such as those controlling site-wide notice or banner status — to be set by regular users. An attacker only needs a valid authenticated session (low-privilege account) and network access to the Discourse instance; no special configuration or user interaction is required. No public proof-of-concept exploit code has been reported (GitHub Advisory, Feedly).
Successful exploitation allows any authenticated user to promote arbitrary topics to site-wide banners or global notices, bypassing administrative controls intended to restrict this capability. This can be abused to spread misinformation, spam, or malicious content to all users of the platform simultaneously. There is no direct impact on confidentiality or system availability, and the vulnerability does not enable lateral movement or data exfiltration; the primary risk is unauthorized content promotion and integrity degradation of the platform (GitHub Advisory, Feedly).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept exploit as of the time of reporting. The EPSS score is approximately 0.053%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Feedly, GitHub Advisory).
/t/{topic_id}.json or POST to the topic creation endpoint) using a proxy tool such as Burp Suite.archetype: "banner" or fields controlling global notice status that are normally restricted to administrators./t/{topic_id}.json or topic creation endpoints from non-administrative user accounts containing unexpected parameters such as archetype=banner or notice-related fields./admin/site_settings) that were not created by administrators; audit logs showing topic attribute changes by regular users.Administrators should upgrade Discourse to one of the patched versions: 2025.12.2, 2026.1.1, or 2026.2.0. There are no practical configuration-based workarounds available to prevent this behavior without applying the patch. As an interim measure, administrators should audit recent changes to site banners and global notices in the admin panel to identify any unauthorized topic promotions that may have already occurred (GitHub Advisory).
The vulnerability was disclosed by Discourse maintainer davidtaylorhq via a GitHub Security Advisory on February 26, 2026, and rated Low severity by the project. Coverage has been limited to automated vulnerability tracking services such as Vulners, CVEFeed, and VulDB, with no notable independent researcher commentary or significant media coverage identified (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."