CVE-2026-45788
Title: Secured Uploads Information Disclosure
Information Disclosure
Proof Of Concept
No public PoC currently indexed for CVE-2026-45788.
CWE Category
CWE-200
Published Date
Jul 09, 2026
Modified Date
Jul 14, 2026
Exploit Status
Not Found
Score
6.3
CVSS v4.0
Exploit Probability (EPSS)
0.47%
Vulnerability Summary
CVE-2026-45788: Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, secure uploads could be exposed by pull_hotlinked_images when an attacker knew the secured upload URL and the secure_uploads site setting was enabled. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5.
Impacted Vendors
Reference Links
https://github.com/discourse/discourse/commit/5807c426880eadf248006e851604fc9284327ce5
https://github.com/discourse/discourse/commit/8b4a959b251a856a9c911fb9f2ac34fbc31a7471
https://github.com/discourse/discourse/commit/eff53af26367ae0dcb3a426954d233e8c7449f95
https://github.com/discourse/discourse/commit/fa74e0dec7341a858ab83a1977fa52629bced1aa
https://github.com/discourse/discourse/releases/tag/v2026.1.5
https://github.com/discourse/discourse/releases/tag/v2026.4.2
https://github.com/discourse/discourse/releases/tag/v2026.5.1
https://github.com/discourse/discourse/releases/tag/v2026.6.0
https://github.com/discourse/discourse/security/advisories/GHSA-3876-w96v-8v38
CVSS v4.0
Source Entity
[email protected]
Severity
MEDIUM
6.3
Attack Vector
NETWORK
Complexity
HIGH
Privileges
N/A
Interaction
NONE
Confidentiality
N/A
Integrity
N/A
Availability
N/A
Scope
N/A
RAW VECTOR
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS v3.1
Source Entity
[email protected]
Severity
HIGH
7.5
Attack Vector
NETWORK
Complexity
LOW
Privileges
N/A
Interaction
NONE
Confidentiality
N/A
Integrity
N/A
Availability
N/A
Scope
UNCHANGED
RAW VECTOR
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
Likelihood
Severity
Page /
CVE-2026-45788 Exploits & PoCs (Proof Of Concept)
No public PoCs found in our database for this CVE.
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data updated via NVD.
Attack Vector Matrix
Access Vector
NETWORK
Complexity
HIGH
Privileges
N/A
Interaction
NONE
CVSS Vector String
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Affected Stack
No specific products linked.