CVE-2026-27454
Last modified
CVE-2026-27454 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, requesting /posts/:id.json?version=X bypassed authorization checks on post revisions. EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, requesting /posts/:id.json?version=X bypassed authorization checks on post revisions. The display_post method called post.revert_to directly without verifying whether the revision was hidden or if the user had permission to view edit history. This meant hidden revisions (intentionally concealed by staff) could be read by any user by simply enumerating version numbers. Starting in versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, Discourse looks up the PostRevision and call guardian.ensure_can_see! before reverting, consistent with how the /posts/:id/revisions/:revision endpoint already authorizes access. No known workarounds are available.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Discourse | Discourse | >= 2026.1.0, < 2026.1.2 |
| Discourse | Discourse | >= 2026.2.0, < 2026.2.1 |
| Discourse | Discourse | 2026.3.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-27454?
How severe is CVE-2026-27454?
How do I fix CVE-2026-27454?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-27446Missing Authentication for Critical Function (CWE-306) vulne…9.8
- CVE-2026-27447OpenPrinting CUPS is an open source printing system for Linu…6.3
- CVE-2026-27448pyOpenSSL is a Python wrapper around the OpenSSL library. St…5.3
- CVE-2026-27449Umbraco Engage is a business intelligence platform. A vulner…7.5
- CVE-2026-2745GitLab has remediated an issue in GitLab CE/EE affecting all…8.1
- CVE-2026-27452ASN.1 TypeScript ESM library, including codecs for Basic Enc…5.3
- CVE-2026-27456util-linux is a random collection of Linux utilities. Prior …4.7
- CVE-2026-27457Weblate is a web based localization tool. Prior to version 5…4.3
- CVE-2026-27458LinkAce is a self-hosted archive to collect website links. V…5.4
- CVE-2026-27459pyOpenSSL is a Python wrapper around the OpenSSL library. St…9.8
- CVE-2026-2746SEPPmail Secure Email Gateway before version 15.0.1 does not…5.3
- CVE-2026-27460Tandoor Recipes is an application for managing recipes, plan…6.5
Are you affected by CVE-2026-27454?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
