CVE-2026-47264 | Discourse up to 2026.1.3/2026.3.0/2026.4.0 Setting information disclosure (GHSA-4q5q-6hh6-53x2 / EUVD-2026-36561)
A vulnerability has been found in Discourse up to 2026.1.3/2026.3.0/2026.4.0 and classified as problematic. The impacted element is an unknown function of the component Setting Handler. The manipulation leads to information disclosure.
This vulnerability is documented as CVE-2026-47264. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.