What is CVE-2026-72722?
CVE-2026-72722 affects the open-source Discourse discussion platform. In versions prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, inconsistent enforcement of `Guardian.can_see?` checks when processing internal links allows an authenticated user to access restricted content. Upgrading to the specified versions is recommended.
Azərbaycanca: CVE-2026-72722 açıq mənbəli Discourse müzakirə platformasında aşkarlanıb. Versiya 2026.1.6, 2026.5.2, 2026.6.1 və 2026.7.0-dən əvvəlki versiyalarda daxili linklərin işlənməsi zamanı `Guardian.can_see?` yoxlamaları ardıcıl tətbiq edilmədiyi üçün autentifikasiya olunmuş istifadəçi icazəsiz məlumatlara çıxış əldə edə bilər. Platformanı göstərilən versiyalara yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the Discourse platform are affected by CVE-2026-72722?
All versions prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0 are affected.
What does this vulnerability allow an authenticated user to do?
It allows an authenticated user to access restricted content due to inconsistent enforcement of `Guardian.can_see?` checks when processing internal links.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.