Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-45788

33
FAUCET Score

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, secure uploads could be exposed by pull_hotlinked_images when an attacker knew the secured upload URL and the secure_uploads site setting was enabled. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5.

First published: Jul 9, 2026Last modified: Jul 9, 2026

Impacted Technologies

VendorProductVersion(s)CPE
>= 2026.1.0, < 2026.1.5CPE matchmatch criteria
cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*
>= 2026.4.0, < 2026.4.2CPE matchmatch criteria
cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*
>= 2026.5.0, < 2026.5.1CPE matchmatch criteria
cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*
2026.6.0CPE matchmatch criteria
cpe:2.3:a:discourse:discourse:2026.6.0:*:*:*:latest:*:*:*

CVSS Data

CVSS version used by this source: 4.0

6.3MEDIUM

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
HIGH
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
LOW
VS Integrity
NONE
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.46%
Probability of exploitation in next 30 days
EPSS Percentile
37.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0046 is in the 16th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

References

github.com / discourse/discourse/commit/5807c426880eadf248006e851604fc9284327ce5
Patch
github.com / discourse/discourse/commit/8b4a959b251a856a9c911fb9f2ac34fbc31a7471
Patch
github.com / discourse/discourse/commit/eff53af26367ae0dcb3a426954d233e8c7449f95
Patch
github.com / discourse/discourse/commit/fa74e0dec7341a858ab83a1977fa52629bced1aa
Patch
github.com / discourse/discourse/releases/tag/v2026.1.5
Release Notes
github.com / discourse/discourse/releases/tag/v2026.4.2
Release Notes
github.com / discourse/discourse/releases/tag/v2026.5.1
Release Notes
github.com / discourse/discourse/releases/tag/v2026.6.0
Release Notes
github.com / discourse/discourse/security/advisories/GHSA-3876-w96v-8v38
Vendor Advisory