Discourse
cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*
- >= 0
- >= 2025.11.0-latest
- >= 2025.12.0-latest
- >= 2026.1.0-latest
A privilege escalation vulnerability has been identified in Discourse versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0. This vulnerability allows non-admin moderators to bypass restrictions on email changes, potentially leading to the takeover of non-staff accounts.
Exploitation of this vulnerability could result in unauthorized email changes, allowing non-admin moderators to take over non-staff accounts.
Users can upgrade to Discourse versions 3.5.4, 2025.11.2, 2025.12.1, or 2026.1.0. As an alternative, the 'require_change_email_confirmation' setting can be enabled.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.