CVE-2026-40869 Details
Description
Decidim is a participatory democracy framework. Starting in version 0.19.0 and prior to versions 0.30.5 and 0.31.1, a vulnerability allows any registered and authenticated user to accept or reject any amendments. The impact is on any users who have created proposals where the amendments feature is enabled. This also elevates the user accepting the amendment as the author of the original proposal as people amending proposals are provided coauthorship on the coauthorable resources. Versions 0.30.5 and 0.31.1 fix the issue. As a workaround, disable amendment reactions for the amendable component (e.g. proposals).
A vulnerability in Decidim's amendment handling allows any registered and authenticated user to accept or reject amendments on proposals, impacting users who have enabled the amendments feature. This issue arises because the platform grants coauthorship to users who amend proposals, thereby falsely attributing authorship to those who accept amendments. The vulnerability is present in Decidim versions 0.19.0 prior to 0.30.5 and 0.31.1, with the exception of 0.31.3, which is not vulnerable. The issue can be exploited by simply accepting or rejecting amendments on affected proposals.
Users can update to Decidim versions 0.30.5 or 0.31.1, where this vulnerability has been fixed. Alternatively, the amendments reactions feature can be disabled for the affected component, such as proposals.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/decidim/decidim/commit/1b99136a1c7aa02616a0b54a6ab88d12907a57a9 | [email protected] | Patch |
| https://github.com/decidim/decidim/security/advisories/GHSA-w5xj-99cg-rccm | [email protected] | MitigationPatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-266 | Incorrect Privilege Assignment | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| decidim decidim | >= 0.19.0, < 0.30.5 >= 0.31.0, < 0.31.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 23, 2026 | Initial Analysis | [email protected] |
| Apr 21, 2026 | New CVE Received | [email protected] |