Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, some subscription endpoints lack proper checking for ownership before making changes. This issue is patched in versions 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0. No known workarounds are available.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 28 Jan 2026 19:00:00 +0000

Type Values Removed Values Added
Description Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, some subscription endpoints lack proper checking for ownership before making changes. This issue is patched in versions 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0. No known workarounds are available.
Title Discourse subscriptions are susceptible to takeover
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-01-28T19:28:16.731Z

Reserved: 2025-12-18T18:29:07.309Z

Link: CVE-2025-68479

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-01-28T19:16:23.380

Modified: 2026-01-28T19:16:23.380

Link: CVE-2025-68479

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses