CVE-2026-45775
Undergoing Analysis Undergoing Analysis - In Progress

Path Traversal in Discourse Multisite Backup Handling

Vulnerability report for CVE-2026-45775, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-06-12

Last updated on: 2026-06-15

Assigner: GitHub, Inc.

Description

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, a path traversal vulnerability in Discourse backup handling could allow an authenticated administrator on one site in a multisite deployment to access backup files belonging to another site when backups are stored locally. In affected configurations, an admin on Site A could potentially retrieve sensitive backup data from Site B (same host, multisite) by crafting a backup download request with a traversal payload. This issue has been patched in versions 2026.1.4, 2026.3.1, 2026.4.1, and 2026.5.0-latest.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-06-12
Last Modified
2026-06-15
Generated
2026-07-03
AI Q&A
2026-06-13
EPSS Evaluated
2026-07-01
NVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
discourse discourse From 2026.1.0 (inc) to 2026.1.4 (exc)
discourse discourse From 2026.3.0 (inc) to 2026.3.1 (exc)
discourse discourse From 2026.4.0 (inc) to 2026.4.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a path traversal issue in the Discourse open-source discussion platform's backup handling system. It affects certain versions of Discourse in multisite deployments where backups are stored locally. An authenticated administrator on one site within the multisite setup can exploit this vulnerability to access backup files belonging to another site on the same host by crafting a specially designed backup download request containing a traversal payload.

Impact Analysis

The impact of this vulnerability is that an authenticated administrator on one site in a multisite Discourse deployment could retrieve sensitive backup data from another site on the same host. This could lead to unauthorized access to potentially sensitive or confidential information contained in those backups, compromising data confidentiality.

Mitigation Strategies

To mitigate this vulnerability, you should upgrade your Discourse installation to one of the patched versions: 2026.1.4, 2026.3.1, 2026.4.1, or 2026.5.0-latest.1.

This will prevent authenticated administrators on one site in a multisite deployment from accessing backup files belonging to another site via path traversal attacks.

Compliance Impact

This vulnerability allows an authenticated administrator on one site in a multisite deployment to access backup files belonging to another site when backups are stored locally. Since backup files may contain sensitive data, unauthorized access to these backups could lead to exposure of personal or protected information.

Such unauthorized access to sensitive backup data could potentially violate data protection regulations and standards like GDPR and HIPAA, which require strict controls over access to personal and protected health information.

Therefore, this vulnerability may negatively impact compliance with these regulations by enabling unauthorized data access within a multisite environment.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-45775. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart