CVE-2026-32114: Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, there is an Insecure Direct Object Reference (IDOR) vulnerability that allows any authe...

Added to the CISA Known Exploited Vulnerabilities catalog on 20 Mar 2026. Vendor: AI/ML. Product: LLM. CVSS score: 4.3.

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, there is an Insecure Direct Object Reference (IDOR) vulnerability that allows any authenticated user to access metadata about AI personas, features, and LLM models by providing their iden...

Required action: Review and patch if applicable to your AI infrastructure.