CVE-2026-72732 | Discourse prior 2026.1.6/2026.5.2/2026.6.1/2026.7.0 TemplatesSerializer templates_serializer.rb access control
A vulnerability, which was classified as problematic, has been found in Discourse. This affects an unknown part of the file plugins/discourse-templates/app/serializers/discourse_templates/templates_serializer.rb of the component TemplatesSerializer. This manipulation causes improper access controls.
The identification of this vulnerability is CVE-2026-72732. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More