---
cve: "CVE-2026-45775"
severity: "MEDIUM"
cvss: 6.8
epss: "32%"
vendor: "discourse"
kev: false
exploited: false
published: "2026-06-12 20:25:33"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-16T12:50:42+02:00"
---

# CVE-2026-45775

> 6.8 MEDIUM · 🧪 PoC

## Beschreibung

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, a path traversal vulnerability in Discourse backup handling could allow an authenticated administrator on one site in a multisite deployment to access backup files belonging to another site when backups are stored locally. In affected configurations, an admin on Site A could potentially retrieve sensitive backup data from Site B (same host, multisite) by crafting a backup download request with a traversal payload. This issue has been patched in versions 2026.1.4, 2026.3.1, 2026.4.1, and 2026.5.0-latest.1.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Hoch | good |
| UI Interaktion | Keine | bad |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Keine | good |
| A Verfügbarkeit | Keine | good |

## Patch verfügbar (OSV)

- ec5d54b3291729ec201615c64d954545000896b9 (Commit)
- 211de17ca39dec7bcb6afebdc9c79cebdc0b4495 (Commit)

## Referenzen

- <https://github.com/discourse/discourse/security/advisories/GHSA-5j6v-4x6g-9pg5>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-45775) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
