PT-2026-60064 · Decidim+2 · Decidim+1

CVE-2026-45086

·

Published

2026-07-13

·

Updated

2026-08-03

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Decidim versions 0.31.1 through 0.31.4 Decidim version 0.32.0.rc1
Description An authorization bypass allows a normal participant to access the demographics questionnaire editor without the required administrator privileges. By directly loading the endpoint '/admin/demographics/questions/edit questions', a low-privilege user can reach the protected interface and make changes to the questionnaire, as the system fails to verify if the caller is an administrator.
Recommendations Update Decidim versions 0.31.1 through 0.31.4 to version 0.31.5. Update Decidim version 0.32.0.rc1 to version 0.32.0.rc2. As a temporary workaround, disable the decidim-demographics module.

Exploit

Fix

Missing Authorization

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45086
GHSA-VQ6J-HJ8W-7V39

Affected Products

Decidim
Decidim-Demographics