
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33424 is an incorrect authorization vulnerability in Discourse, an open-source discussion platform, that allows an attacker to grant access to a private message (PM) topic via invites even after their own access to that PM has been revoked. It affects Discourse versions 2026.1.0 through 2026.1.1, 2026.2.0, and 2026.3.0-latest (unpatched). The vulnerability was published on March 21, 2026, with patches released the same period. It carries a CVSS v3.1 base score of 5.9 (Medium) per the GitHub Security Advisory, or 4.3 (Medium) per NVD scoring (GitHub Advisory).
The root cause is classified as CWE-863 (Incorrect Authorization): Discourse fails to properly validate whether an inviting user still holds access to a private message topic before allowing them to extend invitations to others. When a user's access to a PM is revoked, the platform does not invalidate their ability to issue invites for that same topic, creating a persistent authorization bypass. Exploitation requires the attacker to have previously held high privileges on the PM topic, and also requires user interaction (the invited party must accept the invite) over an adjacent network context (GitHub Advisory).
Successful exploitation allows an attacker whose PM access has been revoked to continue granting third-party users access to the private message topic, resulting in unauthorized disclosure of private message content (high confidentiality impact) and unauthorized modification of access controls (high integrity impact), with a low availability impact. This could expose sensitive communications intended to be restricted after the attacker's removal, and may allow further propagation of unauthorized access if the newly invited users also misuse their access (GitHub Advisory).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.014% (0.000140), indicating a very low probability of exploitation in the near term. Exploitation requires the attacker to have previously held high privileges on the targeted PM topic and requires user interaction, significantly limiting the attack surface (GitHub Advisory).
/t/{topic_id}/invite or similar endpoints) initiated by users who no longer appear in the PM's allowed-users list; audit log entries for PM topic access grants from revoked users.Discourse has released patches addressing this vulnerability. Administrators should upgrade to version 2026.1.2 (for 2026.1.x branch), 2026.2.1 (for 2026.2.x branch), or 2026.3.0-latest.1 (for 2026.3.x branch). No known configuration-based workarounds are available for unpatched versions. As a precautionary measure, administrators should review access logs for private message topics to identify any unauthorized invite activity that may have occurred prior to patching (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."