CVE-2026-72722 | Discourse up to 2026.1.5/2026.5.1/2026.6.0 privileges management
A vulnerability identified as problematic has been detected in Discourse up to 2026.1.5/2026.5.1/2026.6.0. This vulnerability affects the function TopicLink.extract_from/TopicLink.ensure_entry_for/TopicLink.duplicate_lookup. Performing a manipulation results in improper privilege management.
This vulnerability was named CVE-2026-72722. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.VulDB Recent EntriesRead More