CVE-2026-34947
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-34947 is an information disclosure vulnerability in Discourse, the open-source discussion platform, where staged user custom fields and usernames are exposed on public invite pages without requiring email verification. It affects Discourse versions 2026.1.0-latest through before 2026.1.3, 2026.2.0-latest through before 2026.2.2, and 2026.3.0-latest (pre-release). The vulnerability was published on April 3, 2026, and patched versions were released shortly after. It carries a CVSS v3.1 base score of 5.3 (Medium) and a CVSS v4.0 base score of 2.7 (Low) (GitHub Advisory, Red Hat).

Technical details

The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). Discourse's public invite page endpoint improperly returns staged user data — including custom profile fields and usernames — without first verifying that the requesting party has confirmed their email address. Because invite pages are publicly accessible by design, any unauthenticated network actor can query these pages and retrieve the exposed user data. No authentication, special privileges, or user interaction is required to trigger the information leak (GitHub Advisory).

Impact

Successful exploitation results in unauthorized disclosure of staged user custom fields and usernames to unauthenticated parties. Staged users are accounts that have been created but have not yet completed email verification, meaning their data may include personally identifiable information entered during account setup. The confidentiality impact is limited in scope — there is no integrity or availability impact — but the exposure could facilitate user enumeration, targeted phishing, or privacy violations depending on the nature of the custom fields configured by the Discourse instance (GitHub Advisory).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.042%, indicating a very low probability of exploitation in the near term. The CVSSv4 exploit maturity is rated "UNREPORTED," and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The attack requires no authentication and no user interaction, making it trivially accessible to any network-connected attacker, but the limited impact constrains its attractiveness as an exploitation target (GitHub Advisory).

Exploitation steps

  1. Identify target: Locate a publicly accessible Discourse instance running a vulnerable version (2026.1.0–2026.1.2, 2026.2.0–2026.2.1, or 2026.3.0 pre-patch).
  2. Obtain or enumerate invite links: Discover public invite page URLs, which may be shared openly or guessable via token enumeration.
  3. Access the invite page unauthenticated: Send an HTTP GET request to the public invite page endpoint without any authentication headers or session cookies.
  4. Extract exposed data: Parse the HTTP response for staged user custom fields and usernames returned by the server without email verification checks.
  5. Leverage disclosed data: Use the harvested usernames and custom field data for user enumeration, targeted social engineering, or phishing campaigns against the affected community (GitHub Advisory).

Indicators of compromise

  • Network: Unusual or repeated unauthenticated HTTP GET requests to Discourse invite page endpoints (e.g., /invites/<token>) from unfamiliar IP addresses or automated user agents.
  • Logs: Discourse application logs showing high-frequency access to invite URLs without subsequent account creation or email verification events, potentially indicating automated enumeration.
  • Logs: Access log entries with no associated session or authentication tokens repeatedly hitting invite-related routes.

Mitigation and workarounds

Discourse has released patched versions addressing this vulnerability: 2026.1.3, 2026.2.2, and 2026.3.0. The recommended remediation is to upgrade to the latest patched version for the applicable release branch. No configuration-based workaround is available; upgrading is the only supported fix (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-78662HIGH7.5
  • Docker logoDocker
  • cilium-fips-1.20
NoYesSep 02, 2026
CVE-2026-56855HIGH7.5
  • Docker logoDocker
  • argo-workflows-fips-4.0
NoYesSep 02, 2026
CVE-2026-84642HIGH7.5
  • NixOS logoNixOS
  • thunderbird
NoYesSep 01, 2026
CVE-2026-84641HIGH7.5
  • NixOS logoNixOS
  • thunderbird
NoYesSep 01, 2026
CVE-2026-84640HIGH7.5
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:thunderbird
NoYesSep 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management