What is CVE-2026-72724?
CVE-2026-72724 is an authorization bypass vulnerability in Discourse's chat functionality, where `Chat::Thread` is resolved via `thread_id` without verifying user permissions for the associated `channel_id` in `plugins/chat/lib/chat/onebox_handler.rb`. Affected versions prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0 should be updated immediately to prevent unauthorized access.
Azərbaycanca: CVE-2026-72724, Discourse platformunda chat funksionallığında aşkarlanmış səlahiyyət yoxlaması zəifliyidir. Bu boşluq, 'plugins/chat/lib/chat/onebox_handler.rb' faylında istifadəçinin kanalı önizləmə icazəsi yoxlanmadan `Chat::Thread`-ə giriş imkanı yaradır. Təsirə məruz qalan versiyaları işlədən təşkilatlar dərhal 2026.1.6, 2026.5.2, 2026.6.1 və ya 2026.7.0 versiyalarına yeniləmə etməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which component of Discourse does CVE-2026-72724 affect?
The vulnerability affects the chat functionality of the Discourse platform, specifically in the `plugins/chat/lib/chat/onebox_handler.rb` file.
To which versions should Discourse be updated to fix this vulnerability?
Affected systems should be updated to versions 2026.1.6, 2026.5.2, 2026.6.1, or 2026.7.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.