CVE-2026-27151 is a low-severity vulnerability affecting Discourse versions prior to 2025.12.2, 2026.1.1, and 2026.2.0. It allows high-privileged users (TL4 and category group moderators) to bypass write permissions on destination topics when moving posts. This could lead to unauthorized content placement in restricted categories, but does not impact confidentiality or availability. There is no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2025.12.2CPE matchmatch criteria | cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:* | ||
>= 2026.1.0, < 2026.1.1CPE matchmatch criteria | cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:* | ||
2026.2.0CPE matchmatch criteria | cpe:2.3:a:discourse:discourse:2026.2.0:*:*:*:latest:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.