Discourse Sensitive Data Exposure Vulnerability for Non-Admin Moderators

Vulnerability

A vulnerability in Discourse versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 allows non-admin moderators to access sensitive information in staff action logs that should be restricted to administrators. The exposed data includes webhook payload URLs and secrets, API key details, site setting changes, private message content, restricted category names and structures, and private chat channel titles. This access enables moderators to bypass intended access controls and extract confidential information by monitoring the staff action logs. Additionally, leaked webhook secrets could be used to spoof webhook events to integrated services.

Impact

The vulnerability allows non-admin moderators to access and extract sensitive information from staff action logs, bypassing intended access controls. This could lead to unauthorized disclosure of confidential data, including private messages and restricted category information.

Remediation

Users can upgrade to Discourse versions 3.5.4, 2025.11.2, 2025.12.1, or 2026.1.0. As a workaround, site administrators should review and limit moderator appointments to fully trusted users.

Added: Jan 28, 2026, 9:23 PM
Updated: Jan 28, 2026, 9:23 PM

Vulnerability Rating

Custom Algorithm
spread
2.4
impact
2.5
exploitability
3.3
remediation
8.3
relevance
2.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.