CVE Database
/

CVE-2025-69289

Back to search

CVE-2025-69289

Published: Jan 28, 2026

Modified: Jan 28, 2026

PUBLISHED

Description

Discourse is an open source discussion platform. A privilege escalation vulnerability in versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 allows a non-admin moderator to bypass email-change restrictions, allowing a takeover of non-staff accounts. This issue is patched in versions 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0. As a workaround, ensure moderators are trusted or enable the "require_change_email_confirmation" setting.

VendorProductVersions

discourse

discourse

affected
< 3.5.4
affected
>= 2025.11.0-latest, < 2025.11.2
affected
>= 2025.12.0-latest, < 2025.12.1
affected
>= 2026.1.0-latest, < 2026.1.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now