CVE-2026-55704
Received
Received - Intake
Information Disclosure in Discourse Group Activity
Vulnerability report for CVE-2026-55704, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-17
Last updated on: 2026-08-17
Assigner: GitHub, Inc.
Description
Description
Discourse is an open-source discussion platform. Prior o 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, users who were allowed to view a groupβs activity, but were not permitted to see shared drafts, could still receive shared-draft entries through the group posts and group mentions endpoints. This could disclose shared-draft topic titles and post excerpt/content, resulting in an information disclosure of unpublished draft material. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| discourse | discourse | to 2026.1.6|end_excluding=2026.5.2|end_excluding=2026.6.1|end_excluding=2026.7.0 (exc) |
| discourse | discourse | 2026.1.6 |
| discourse | discourse | 2026.5.2 |
| discourse | discourse | 2026.6.1 |
| discourse | discourse | 2026.7.0 |
| discourse | discourse | to 2026.1.6 (exc) |
| discourse | discourse | to 2026.5.2 (exc) |
| discourse | discourse | to 2026.6.1 (exc) |
| discourse | discourse | to 2026.7.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |