CVE-2026-46413 | Discourse up to 2026.1.4/2026.4.1/2026.5.0 ExternalUploadManager unrestricted upload

SecurityVulns

A vulnerability, which was classified as critical, has been found in Discourse up to 2026.1.4/2026.4.1/2026.5.0. Affected is an unknown function of the component ExternalUploadManager. Performing a manipulation results in unrestricted upload.

This vulnerability was named CVE-2026-46413. The attack may be initiated remotely. There is no available exploit.VulDB Recent EntriesRead More