What is CVE-2026-55704?
A vulnerability in the Discourse platform allowed users, who lacked permission to view shared drafts but had access to a group's activity, to receive shared-draft entries via group posts and group mentions endpoints. Applying the security update is recommended.
Azərbaycanca: Discourse platformasında zəiflik aşkar edilib. İcazələrə baxmayaraq istifadəçilər shared draft qeydlərinə group posts/mentions endpoint-ləri vasitəsilə daxil ola bilər. Təhlükəsizlik yeniləməsini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ1
What did the CVE-2026-55704 vulnerability in Discourse allow?
Users without proper permission could access shared-draft entries via group posts and group mentions endpoints.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.