CVE-2026-72723 | Discourse up to 2026.1.5/2026.5.1/2026.6.0 Navigation Menu Tags /site.json information disclosure
A vulnerability labeled as problematic has been found in Discourse up to 2026.1.5/2026.5.1/2026.6.0. This issue affects the function SiteSerializer.anonymous_default_navigation_menu_tags of the file /site.json of the component Navigation Menu Tags. Executing a manipulation can lead to information disclosure.
The identification of this vulnerability is CVE-2026-72723. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.VulDB Recent EntriesRead More