Discourse Group Notification Level Modification Vulnerability

Vulnerability

A vulnerability exists in Discourse, an open-source discussion platform, allowing staff to change any user's group notification level. This issue is present in versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2. The vulnerability has been patched in the mentioned versions, but no workarounds are available.

Impact

Exploitation of this vulnerability allows staff to arbitrarily modify users' group notification levels, potentially leading to unauthorized changes in user engagement or visibility within discussions.

Remediation

Users can upgrade to Discourse versions 2026.3.0-latest.1, 2026.2.1, or 2026.1.2 to address this vulnerability.

Added: Mar 20, 2026, 11:20 PM
Updated: Mar 20, 2026, 11:20 PM

Vulnerability Rating

Custom Algorithm
spread
2.4
impact
0.6
exploitability
2.8
remediation
7.7
relevance
4.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.