CVE-2026-33291 | Discourse up to 2026.1.1/2026.2.0/2026.3.0-latest Zendesk Plugin authorization (GHSA-p26h-jqr4-r6j7)
A vulnerability categorized as critical has been discovered in Discourse up to 2026.1.1/2026.2.0/2026.3.0-latest. The impacted element is an unknown function of the component Zendesk Plugin. Such manipulation leads to incorrect authorization.
This vulnerability is traded as CVE-2026-33291. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.