CVE Vulnerabilities

CVE-2026-26077

Improper Authentication

Published: Feb 26, 2026 | Modified: Mar 02, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, several webhook endpoints (SendGrid, Mailjet, Mandrill, Postmark, SparkPost) in the WebhooksController accepted requests without a valid authentication token when no token was configured. This allowed unauthenticated attackers to forge webhook payloads and artificially inflate user bounce scores, potentially causing legitimate user emails to be disabled. The Mailpace endpoint had no token validation at all. Starting in versions 2025.12.2, 2026.1.1, and 2026.2.0, all webhook endpoints reject requests with a 406 response when no authentication token is configured. As a workaround, ensure that webhook authentication tokens are configured for all email provider integrations in site settings (e.g., sendgrid_verification_key, mailjet_webhook_token, postmark_webhook_token, sparkpost_webhook_token). Theres no current workaround for mailpace before getting this fix.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
DiscourseDiscourse*2025.12.0 (excluding)
DiscourseDiscourse2026.1.0 (including)2026.1.1 (excluding)
DiscourseDiscourse2026.2.0 (including)2026.2.0 (including)

Potential Mitigations

References