CVE-2026-72726: Discourse
Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an authenticated user could eavesdrop on private AI bot conversations through the AI bot reply stream. The issue is fixed in 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.
Affected products
- Discourse Discourse: before 2026.1.6 (fixed in 2026.1.6); from 2026.5.0, before 2026.5.2 (fixed in 2026.5.2); from 2026.6.0, before 2026.6.1 (fixed in 2026.6.1)
Published 2026-08-10. Last modified 2026-09-08.