CVE-2025-68933 | Discourse prior 3.5.4/2025.11.2/2025.12.1/2026.1.0 Private Message authorization
A vulnerability labeled as problematic has been found in Discourse. This affects an unknown part of the component Private Message Handler. The manipulation results in incorrect authorization.
This vulnerability is known as CVE-2025-68933. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.