PT-2026-60068 · Decidim+2 · Decidim+1

CVE-2026-45376

·

Published

2026-07-13

·

Updated

2026-08-03

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Decidim versions prior to 0.30.9 Decidim versions 0.31.0 through 0.31.4 Decidim version 0.32.0.rc1
Description An authenticated organization administrator can execute blind PostgreSQL expressions and infer data through timing differences. The issue occurs because the application interpolates the term parameter into raw Arel.sql ORDER BY similarity expressions before sanitization is applied. This allows a crafted search string to be executed by the database as part of the sort expression.
API Endpoint: GET /admin/organization/users Vulnerable Parameter: term
Recommendations Update to version 0.30.9. Update to version 0.31.5. Update to version 0.32.0.rc2. Review administrator access and ensure permissions are not granted to untrustworthy users.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45376
GHSA-JVQQ-CVH4-XM37

Affected Products

Decidim
Decidim-Admin