SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-53960

MEDIUM · CVSS 5.3 EPSS 0.19% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-17 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

The vulnerability affects the Discourse open-source discussion platform, where hidden or unviewable first-post content is inadvertently exposed in the publicly accessible Q&A JSON-LD structured data. This could lead to unauthorized disclosure of sensitive information to unauthenticated users and search-engine crawlers. Organizations using affected versions should prioritize updating to the fixed releases (2026.1.6, 2026.5.2, 2026.6.1, or 2026.7.0) to mitigate potential information leaks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-53960
Severity
MEDIUM
CVSS
5.3
EPSS
0.19%

Original NVD Description

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, hidden or otherwise unviewable first-post content was leaked as an excerpt in the publicly-served Q&A (QAPage) JSON-LD structured data, exposing it to any unauthenticated visitor and to search-engine crawlers. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.