CVE-2026-28218 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, fail-open access control in Data Explorer plugin allows an…
Medium CVSS: 5.3

CVE-2026-28218

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, fail-open access control in Data Explorer plugin allows any authenticated user to execute SQL queries that have no explicit group assignments, including built-in system queries. Versions 2025.12.2, 2026.1.1, and 2026.2.0 patch the issue. As a workaround, either explicitly set group permissions on each Data Explorer query that doesn't have permissions, or disable discourse-data-explorer plugin.
Vendor
Discourse
Product
Discourse
CWE
CWE-284
Yayın Tarihi
2026-02-26 22:20:49
Güncelleme
2026-03-02 18:12:49
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar