CVE Database
/

CVE-2026-27166

Back to search

CVE-2026-27166

Published: Mar 19, 2026

Modified: Mar 21, 2026

PUBLISHED

CVSS v3.1

4.1

MEDIUM

Description

Discourse is an open source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1 and 2026.1.2, insufficient cleanup in the default Codepen allowed iframes value allows an attacker to trick a user into changing the URL of the main page. This issue has been fixed in versions 2026.3.0-latest.1, 2026.2.1 and 2026.1.2. To workaround this issue, remove Codepen from the list of allowed iframes.

VendorProductVersions

discourse

discourse

affected
< 2026.3.0-latest.1
affected
>= 2026.2.0-latest, < 2026.2.1
affected
>= 2026.1.0-latest, < 2026.1.2

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

Low

User Interaction

Required

Scope

Changed

Confidentiality

None

Integrity

Low

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now