CVE-2026-44784 | Discourse up to 2026.1.3/2026.3.0/2026.4.0 SMTP Password name/logs.json information disclosure (GHSA-94c5-j24g-r99f / EUVD-2026-36587)
A vulnerability classified as problematic has been found in Discourse up to 2026.1.3/2026.3.0/2026.4.0. This vulnerability affects unknown code of the file name/logs.json of the component SMTP Password Handler. This manipulation causes information disclosure.
This vulnerability is tracked as CVE-2026-44784. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.