CVE-2026-33408
Title: Discourse PM/Private Category Post Edit Information Disclosure
Other
Proof Of Concept
No public PoC currently indexed for CVE-2026-33408.
CWE Category
CWE-862
Published Date
Mar 19, 2026
Modified Date
Mar 24, 2026
Exploit Status
Not Found
Score
2.2
CVSS v3.1
Exploit Probability (EPSS)
0.01%
Vulnerability Summary
CVE-2026-33408: Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, moderators were able to see the first 40 characters of post edits in PMs and private categories. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch. No known workarounds are available.
Impacted Vendors
Reference Links
https://github.com/discourse/discourse/commit/3bf3793a708662716c0a4eaf64ae091abe71ab4c
https://github.com/discourse/discourse/commit/473288219e93cd17576cf15e4f0b9e388a31d0c1
https://github.com/discourse/discourse/commit/62721429d4402505d21280bcbe5894032447d800
https://github.com/discourse/discourse/security/advisories/GHSA-wf9r-386h-g29c
CVSS v3.1
Source Entity
[email protected]
Severity
LOW
2.7
Attack Vector
NETWORK
Complexity
LOW
Privileges
N/A
Interaction
NONE
Confidentiality
N/A
Integrity
N/A
Availability
N/A
Scope
UNCHANGED
RAW VECTOR
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
CVSS v3.1
Source Entity
[email protected]
Severity
LOW
2.2
Attack Vector
NETWORK
Complexity
HIGH
Privileges
N/A
Interaction
NONE
Confidentiality
N/A
Integrity
N/A
Availability
N/A
Scope
UNCHANGED
RAW VECTOR
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
Likelihood
Severity
Page /
CVE-2026-33408 Exploits & PoCs (Proof Of Concept)
No public PoCs found in our database for this CVE.
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data updated via NVD.
Attack Vector Matrix
Access Vector
NETWORK
Complexity
LOW
Privileges
N/A
Interaction
NONE
CVSS Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Affected Stack
No specific products linked.