Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, there is possible channel membership inference from chat user search without authorization. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.
We have discovered 909 live websites that are affected by CVE-2026-32618.
| Product | |
| Category | Message Boards |
| Vulnerable Domains | 909 live websites (20% of Discourse install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 4 versions ( 5.63% of all versions) |
| 491 websites | |
| 200 websites | |
| 40 websites | |
| 25 websites | |
| 18 websites | |
| 16 websites | |
| 15 websites | |
| 11 websites | |
| 10 websites | |
| 10 websites |
| .com | 397 websites |
| .org | 135 websites |
| .net | 45 websites |
| .io | 31 websites |
| .de | 29 websites |
| .fr | 15 websites |
| .co.uk | 13 websites |
| .ch | 12 websites |
| .eu | 10 websites |
| .it | 9 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***********.org | **,*** | ||
| *********.***********.com | **,*** | ||
| ***********.com | ***,*** | ||
| *****.********.com | ***,*** | ||
| *********.*******.org | ***,*** | ||
| *********.de | ***,*** | ||
| ****************.com | ***,*** | ||
| ****.***********.org | ***,*** | ||
| *****.*******.org | ***,*** | ||
| *****.********.com | ***,*** |
FAQ