Sploitus

CVE-2026-27934

No indexed exploits for CVE-2026-27934 yet

Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a lack of visibility checks with a user action API endpoint that results in disclosure of the title and post excerpt to unauthorized users, leading to information disclosure. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch. No known workarounds are available.

Affected products
Discourse
Discourse
< 2026.1.2, 2026.2.1, 2026.3.0
Fix
Available
CVSS 4.0
8.7 HIGH
CVSS 3.1
7.5 HIGH
EPSS
0.3% (17th percentile)
Weakness
CWE-201
NVD status
Analyzed
Published
2026-03-19
CVE-2026-27934 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-27934 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-27934 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.