Sploitus

CVE-2026-26078

No indexed exploits for CVE-2026-26078 yet

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, when the `patreon_webhook_secret` site setting is blank, an attacker can forge valid webhook signatures by computing an HMAC-MD5 with an empty string as the key. Since the request body is known to the sender, the attacker can produce a matching signature and send arbitrary webhook payloads. This allows unauthorized creation, modification, or deletion of Patreon pledge data and triggering patron-to-group synchronization. This vulnerability is patched in versions 2025.12.2, 2026.1.1, and 2026.2.0. The fix rejects webhook requests when the webhook secret is not configured, preventing signature forgery with an empty key. As a workaround, configure the `patreon_webhook_secret` site setting with a strong, non-empty secret value. When the secret is non-empty, an attacker cannot forge valid signatures without knowing the secret.

Affected products
Discourse
Discourse
< 2025.12.0, 2026.1.1, 2026.2.0
Fix
Available
CVSS 3.1
7.5 HIGH
EPSS
0.2% (13th percentile)
Weakness
CWE-639
NVD status
Analyzed
Published
2026-02-26
CVE-2026-26078 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-26078 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-26078 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.