PT-2026-60064 · Decidim+2 · Decidim+1
CVE-2026-45086
·
Published
2026-07-13
·
Updated
2026-08-03
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Decidim versions 0.31.1 through 0.31.4
Decidim version 0.32.0.rc1
Description
An authorization bypass allows a normal participant to access the demographics questionnaire editor without the required administrator privileges. By directly loading the endpoint '/admin/demographics/questions/edit questions', a low-privilege user can reach the protected interface and make changes to the questionnaire, as the system fails to verify if the caller is an administrator.
Recommendations
Update Decidim versions 0.31.1 through 0.31.4 to version 0.31.5.
Update Decidim version 0.32.0.rc1 to version 0.32.0.rc2.
As a temporary workaround, disable the
decidim-demographics module.Exploit
Fix
Missing Authorization
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Decidim
Decidim-Demographics