Discourse - Private User Field Disclosure via Directory Items IDOR
CVE-2026-26265
Verified
Description
Discourse prior to 2025.12.2, 2026.1.1, and 2026.2.0 contains an IDOR vulnerability caused by lack of authorization checks on user_field_ids parameter in DirectoryItemsController#index, letting any user retrieve private user field values, exploit requires no authentication.
Severity
High
CVSS Score
7.5
Exploit Probability
1%
Affected Product
discourse
Published Date
September 14, 2026
Template Author
str4k3r
CVE-2026-26265.yaml
7.5Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE ID:
cve-2026-26265
CWE ID:
cwe-639
Remediation Steps
Update to versions 2025.12.2, 2026.1.1, or 2026.2.0 or later.