Report: CVE-2026-30888 - Discourse has moderator privilege escalation via arbitrary post_id in suspend/si...

Report: CVE-2026-30888 - Discourse has moderator privilege escalation via arbitrary post_id in suspend/si...

CVE ID :CVE-2026-30888 Published : March 20, 2026, 3:15 a.m. | 36 minutes ago Description :Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 allow a moderator to edit site policy documents (ToS, guidelines, privacy policy) that they are explicitly prohibited from modifying. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch. No known workarounds are available. Severity: 2.2 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
LOW
Published
March 20, 2026