CVE-2026-26973 describes an Insecure Direct Object Reference (IDOR) vulnerability in Discourse, affecting versions prior to 2025.12.2, 2026.1.1, and 2026.2.0, specifically when the enable_category_group_moderation setting is enabled. This flaw allows a user in a category moderation group to create or delete notes on any reviewable item, even those outside their moderated categories, due to an unscoped lookup. The vulnerability has a CVSS score of 4.3 (Medium), indicating a low attack complexity and requiring low privileges, but with no confidentiality, integrity, or availability impact. The primary impact is unauthorized modification of reviewable notes. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage are minimal, suggesting low public awareness or interest in this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2025.12.0CPE matchmatch criteria | cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:* | ||
>= 2026.1.0, < 2026.1.1CPE matchmatch criteria | cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:* | ||
2026.2.0CPE matchmatch criteria | cpe:2.3:a:discourse:discourse:2026.2.0:*:*:*:latest:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.