HIGH
CVE-2026-45414
CVSS
8.5
Description
Decidim is a participatory democracy framework. Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, JWT-backed API authentication is not bound to the organization selected by the current host, allowing a JWT issued for one tenant to be replayed against another tenant’s API to read participantDetails data and reach the proposal.answer mutation path. This issue is fixed in versions 0.31.5 and 0.32.0.rc2.
Weakness (CWE)
CWE-639
Authorization Bypass (IDOR)
CWE-863
Incorrect Authorization
EPSS Score
0.32%
Probability of exploitation in next 30 days
25.6th percentile
References
https://github.com/decidim/decidim/commit/023e206127c984a501345676e4789b31ddd115a1
https://github.com/decidim/decidim/commit/226dc94894e6a3c030e4638c8b3441ee7199643c
https://github.com/decidim/decidim/releases/tag/v0.31.5
https://github.com/decidim/decidim/releases/tag/v0.32.0.rc2
https://github.com/decidim/decidim/security/advisories/GHSA-r3v7-5x4c-c69q
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.