Skip to main content
Vulnerability Database/CVE-2026-84302

CVE-2026-84302: Discourse AI Privilege Escalation Vulnerability

CVE-2026-84302 is a privilege escalation vulnerability in Discourse AI that allows moderators to access private message content outside their permissions. This article covers the technical details, affected versions, security impact, and mitigation strategies.

Published:

CVE-2026-84302 Overview

Discourse, an open-source discussion platform, contains a missing authorization flaw [CWE-862] in its AI reviewable queue. Private-message reviewables generated by Discourse AI appeared in moderator review queues without validating whether the moderator was a participant in the underlying private-message topic. A moderator who should not have access to the conversation could read its confidential content. Depending on the reviewable action available, the moderator could also close the topic or delete a post. The issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.

Critical Impact

Authenticated moderators can read, close, or modify private-message content outside their permitted audience when a Discourse AI reviewable is associated with the message.

Affected Products

  • Discourse prior to 2026.1.6 (2026.1.x branch)
  • Discourse prior to 2026.5.2 and 2026.6.1 (2026.5.x and 2026.6.x branches)
  • Discourse prior to 2026.7.0 (current stable)

Discovery Timeline

  • 2026-09-24 - CVE CVE-2026-84302 published to NVD
  • 2026-09-24 - Last updated in NVD database

Technical Details for CVE-2026-84302

Vulnerability Analysis

The flaw resides in Discourse's reviewable visibility filtering. The Reviewable model scoped the moderator review queue by category permissions and moderator role, but did not exclude reviewables whose source topic was a private message the current user could not access. Discourse AI generates reviewables for flagged content, including content within private messages. When those reviewables surfaced in the review queue, the moderator viewing them could read the quoted private-message content and, in some cases, perform actions against the underlying topic. Exploitation requires an authenticated moderator account and the pre-existing presence of a Discourse AI reviewable tied to a private message.

Root Cause

The root cause is a missing authorization check [CWE-862] in the reviewable query scope. The query joined category moderation groups and filtered by allowed_category_ids, but never consulted the private-message guardian to confirm the moderator was a participant in or had been granted access to the PM topic. Private-message access control was decoupled from reviewable visibility.

Attack Vector

An authenticated moderator who is not a participant in a private message navigates to the review queue. Any Discourse AI reviewable associated with that private message is rendered to the moderator, exposing the content. Where the reviewable supports destructive actions, the moderator can close the topic or delete posts in the private conversation.

ruby
# Patch: app/models/reviewable.rb
# Before — scope filtered only by category/moderator role
result
  .left_joins(category: :category_moderation_groups)
  .where(
    "(reviewables.reviewable_by_moderator AND :moderator) OR (category_moderation_groups.group_id IN (:group_ids))",
    moderator: user.moderator?,
    group_ids: group_ids,
  )
  .where(
    "reviewables.category_id IS NULL OR reviewables.category_id IN (?)",
    Guardian.new(user).allowed_category_ids,
  )

# After — reviewables tied to PMs hidden from the user are excluded
result =
  result
    .left_joins(category: :category_moderation_groups)
    .where(
      "(reviewables.reviewable_by_moderator AND :moderator) OR (category_moderation_groups.group_id IN (:group_ids))",
      moderator: user.moderator?,
      group_ids: group_ids,
    )
    .where(
      "reviewables.category_id IS NULL OR reviewables.category_id IN (?)",
      Guardian.new(user).allowed_category_ids,
    )

exclude_private_messages_hidden_from(result, user)

Source: Discourse Commit 1566d045

Detection Methods for CVE-2026-84302

Indicators of Compromise

  • Review queue access events by moderator accounts correlated with private-message topics they are not participants in.
  • Topic close or post delete events on private-message topics performed by non-participant moderators.
  • Unexpected Reviewable action logs referencing PM topic IDs outside the moderator's permitted scope.

Detection Strategies

  • Audit the Discourse staff_action_logs table for delete_post and close_topic actions where the target topic archetype is private_message.
  • Cross-reference reviewable view events with topic allowed-user lists to flag out-of-audience access.
  • Alert on any moderator interacting with Discourse AI reviewables tied to private messages they do not appear in.

Monitoring Recommendations

  • Forward Discourse application and staff-action logs to a centralized log platform for correlation with user and topic metadata.
  • Baseline moderator reviewable activity and alert on spikes targeting the private_message archetype.
  • Review Discourse AI reviewable creation volume to understand exposure during the pre-patch window.

How to Mitigate CVE-2026-84302

Immediate Actions Required

  • Upgrade Discourse to 2026.1.6, 2026.5.2, 2026.6.1, or 2026.7.0 depending on your release branch.
  • Audit moderator activity against private-message topics since Discourse AI reviewables were enabled in your environment.
  • Rotate or review access for any moderator accounts suspected of exploiting the exposed reviewables.

Patch Information

Discourse resolved the issue by scoping private-message reviewables to the audience permitted to access the underlying PM topic. See the GitHub Security Advisory GHSA-3rx9-fqgh-wfpc and Discourse Pull Request #42091. The fix is distributed across commits 1566d045, 23488b72, 38d10c0e, and b323702d.

Workarounds

  • Temporarily disable Discourse AI features that generate reviewables for private messages until the patch is applied.
  • Reduce the moderator population and limit the reviewable_by_moderator scope to trusted staff while planning the upgrade.
  • Clear or triage any outstanding AI-generated reviewables tied to private-message topics before restoring normal moderator access.
bash
# Upgrade an existing Discourse Docker deployment to a patched release
cd /var/discourse
git pull
# Pin to a patched version in containers/app.yml, for example:
#   version: v2026.7.0
./launcher rebuild app

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.