CVE-2026-32618

Discourse: Unauthorized channel membership inference via excluded_memberships_channel_id

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, there is possible channel membership inference from chat user search without authorization. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.


We have discovered 909 live websites that are affected by CVE-2026-32618.

Run a Free Instant Scan




Affected Software

Product  Discourse
Category Message Boards
Vulnerable Domains909 live websites (20% of Discourse install base)
Vulnerable Versions
  • from 2026.1 through 2026.1.3
  • from 2026.2 through 2026.2.2
  • from 2026.3 through 2026.3
Vulnerable Versions Count4 versions ( 5.63% of all versions)


Common Weakness Enumeration

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor



Details

  • Published - Mar 31, 2026
  • Updated - Apr 3, 2026

Website Distribution by Country

Number of websites using CVE-2026-32618
United States491 websites



Germany200 websites
France40 websites
GB25 websites
Singapore18 websites
Switzerland16 websites
Netherlands15 websites
Russia11 websites
Canada10 websites
China10 websites

Website Distribution by TLD

Number of websites using CVE-2026-32618
.com397 websites
.org135 websites
.net45 websites
.io31 websites
.de29 websites
.fr15 websites
.co.uk13 websites
.ch12 websites
.eu10 websites
.it9 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-32618

Top websites that are affected by CVE-2026-32618. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.org United States**,***
*********.***********.com United States**,***
***********.com United States***,***
*****.********.com Germany***,***
*********.*******.org Germany***,***
*********.de Germany***,***
****************.com Germany***,***
****.***********.org United States***,***
*****.*******.org Germany***,***
*****.********.com Latvia***,***
See full domain list

FAQ

CVE-2026-32618 is Exposure of Sensitive Information to an Unauthorized Actor in Discourse
A total of 909 websites have been identified as vulnerable to CVE-2026-32618, based on global website indexing conducted by WebTechSurvey.
The Discourse is affected by the CVE-2026-32618 vulnerability.
Discourse versions up to 2026.3 are vulnerable to CVE-2026-32618.
CVE-2026-32618 is resolved in version 2026.3 of Discourse.