What is CVE-2026-72726?
CVE-2026-72726 is a vulnerability in the open-source Discourse discussion platform where an authenticated user could eavesdrop on private AI bot conversations through the AI bot reply stream. Affected versions are those prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0. Upgrading to the fixed versions is recommended to mitigate the issue.
Azərbaycanca: CVE-2026-72726 açıq mənbəli Discourse müzakirə platformasında autentifikasiya olunmuş istifadəçinin, AI bot cavab axını vasitəsilə şəxsi bot söhbətlərini gizlicə dinləyə bilməsi zəifliyidir. Təsirə məruz qalan versiyalar 2026.1.6, 2026.5.2, 2026.6.1 və 2027.7.0-dən əvvəlki versiyalardır. Problemi aradan qaldırmaq üçün göstərilən versiyalara yenilənmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
On which platform was CVE-2026-72726 discovered?
This vulnerability was discovered on the open-source Discourse discussion platform.
Which versions are recommended for upgrading to mitigate CVE-2026-72726?
Upgrading to versions 2026.1.6, 2026.5.2, 2026.6.1, or 2026.7.0 is recommended to mitigate the issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.