Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
6.5
Discourse Webhooks Allow Unauthenticated Access without Token
CVE-2026-26077
Summary
Discourse's webhooks in certain email integrations (SendGrid, Mailjet, Mandrill, Postmark, SparkPost) allowed unauthorized access to modify user emails before version updates. This could cause legitimate users to be blocked. Update your Discourse site settings to require authentication tokens for all email provider integrations to prevent unauthorized access.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions | Fix available |
|---|---|---|---|
| discourse | discourse | <= 2025.12.0 | – |
| discourse | discourse | > 2026.1.0 , <= 2026.1.1 | – |
| discourse | discourse | 2026.2.0 | – |
Original title
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, several webhook endpoints (SendGrid, Mailjet, Mandrill, Postmark, SparkPost) in the `WebhooksCo...
Original description
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, several webhook endpoints (SendGrid, Mailjet, Mandrill, Postmark, SparkPost) in the `WebhooksController` accepted requests without a valid authentication token when no token was configured. This allowed unauthenticated attackers to forge webhook payloads and artificially inflate user bounce scores, potentially causing legitimate user emails to be disabled. The Mailpace endpoint had no token validation at all. Starting in versions 2025.12.2, 2026.1.1, and 2026.2.0, all webhook endpoints reject requests with a 406 response when no authentication token is configured. As a workaround, ensure that webhook authentication tokens are configured for all email provider integrations in site settings (e.g., `sendgrid_verification_key`, `mailjet_webhook_token`, `postmark_webhook_token`, `sparkpost_webhook_token`). There's no current workaround for mailpace before getting this fix.
nvd CVSS3.1
6.5
Vulnerability type
CWE-287
Improper Authentication
Published: 26 Feb 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026