CVE-2025-69289

Discourse has insecure default configuration that allows non-admin moderators to takeover any non-staff account via email change

Discourse is an open source discussion platform. A privilege escalation vulnerability in versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 allows a non-admin moderator to bypass email-change restrictions, allowing a takeover of non-staff accounts. This issue is patched in versions 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0. As a workaround, ensure moderators are trusted or enable the "require_change_email_confirmation" setting.


We have discovered 3,232 live websites that are affected by CVE-2025-69289.

Run a Free Instant Scan




Affected Software

Product  Discourse
Category Message Boards
Vulnerable Domains3,232 live websites (71% of Discourse install base)
Vulnerable Versions
  • from 0 through 3.5.4
  • from 2025.11 through 2025.11.2
  • from 2025.12 through 2025.12.1
  • from 2026.1 through 2026.1
Vulnerable Versions Count64 versions ( 97% of all versions)


Common Weakness Enumeration

CWE-863 Incorrect Authorization



Details

  • Published - Jan 28, 2026
  • Updated - Jan 28, 2026

Website Distribution by Country

Number of websites using CVE-2025-69289
United States1,968 websites



Germany521 websites
France134 websites
Singapore76 websites
GB59 websites
China45 websites
Russia44 websites
Netherlands32 websites
Switzerland29 websites
Canada25 websites

Website Distribution by TLD

Number of websites using CVE-2025-69289
.com1,383 websites
.org576 websites
.net165 websites
.io147 websites
.de86 websites
.ru35 websites
.fr34 websites
.eu29 websites
.co27 websites
.nl23 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-69289

Top websites that are affected by CVE-2025-69289. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.com United States*,***
*********.**********.com United States*,***
*****.******.org Germany*,***
*****.******.com United States*,***
*********.***********.org United States**,***
*********.**********.com United States**,***
*********.******.com Germany**,***
*******.******.com United States**,***
*********.*******.com United States**,***
******************.com United States**,***
See full domain list

FAQ

CVE-2025-69289 is Incorrect Authorization in Discourse
A total of 3,232 websites have been identified as vulnerable to CVE-2025-69289, based on global website indexing conducted by WebTechSurvey.
The Discourse is affected by the CVE-2025-69289 vulnerability.
Discourse versions up to 2026.1 are vulnerable to CVE-2025-69289.
CVE-2025-69289 is resolved in version 2026.1 of Discourse.