CVE-2026-44787 | Discourse up to 2026.1.4/2026.4.1/2026.5.0 Signup Flow primary_group_id improper authentication
A vulnerability marked as critical has been reported in Discourse up to 2026.1.4/2026.4.1/2026.5.0. The affected element is an unknown function of the component Signup Flow. The manipulation of the argument primary_group_id leads to improper authentication.
This vulnerability is traded as CVE-2026-44787. It is possible to initiate the attack remotely. There is no exploit available.VulDB Recent EntriesRead More