Discourse Zendesk Ticket Creation Vulnerability for Inaccessible Topics

Vulnerability

A vulnerability exists in Discourse versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, allowing moderators to create Zendesk tickets for topics they cannot view. This issue affects all forums using the Zendesk plugin.

Impact

This vulnerability allows moderators to bypass visibility restrictions and create Zendesk tickets for topics they do not have access to, potentially leading to unauthorized discussions or actions on those topics.

Remediation

Users can upgrade to Discourse versions 2026.3.0-latest.1, 2026.2.1, or 2026.1.2 to address this vulnerability.

Added: Mar 20, 2026, 11:20 PM
Updated: Mar 20, 2026, 11:20 PM

Vulnerability Rating

Custom Algorithm
spread
2.4
impact
1.5
exploitability
2.9
remediation
7.7
relevance
4.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.