Sploitus

CVE-2026-26077

No indexed exploits for CVE-2026-26077 yet

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, several webhook endpoints (SendGrid, Mailjet, Mandrill, Postmark, SparkPost) in the `WebhooksController` accepted requests without a valid authentication token when no token was configured. This allowed unauthenticated attackers to forge webhook payloads and artificially inflate user bounce scores, potentially causing legitimate user emails to be disabled. The Mailpace endpoint had no token validation at all. Starting in versions 2025.12.2, 2026.1.1, and 2026.2.0, all webhook endpoints reject requests with a 406 response when no authentication token is configured. As a workaround, ensure that webhook authentication tokens are configured for all email provider integrations in site settings (e.g., `sendgrid_verification_key`, `mailjet_webhook_token`, `postmark_webhook_token`, `sparkpost_webhook_token`). There's no current workaround for mailpace before getting this fix.

Affected products
Discourse
Discourse
< 2025.12.0, 2026.1.1, 2026.2.0
Fix
Available
CVSS 3.1
6.5 MEDIUM
EPSS
0.2% (15th percentile)
Weakness
CWE-287
NVD status
Analyzed
Published
2026-02-26
CVE-2026-26077 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-26077 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-26077 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.