CVE-2026-45415 Details
Description
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the /admin/csv_census/census_logs record-management endpoints do not enforce full administrator authorization before rendering or mutating Decidim::Verifications::CsvDatum, allowing a participant manager to create, alter, or remove census records. This issue is fixed in versions 0.30.9, 0.31.5, and 0.32.0.rc2.
A vulnerability exists in Decidim's CSV census record management endpoints, specifically under '/admin/csv_census/census_logs'. In versions prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 prior to 0.32.0.rc2, these endpoints do not fully enforce administrator authorization. This oversight allows participant managers to create, modify, or delete census records, potentially corrupting verification data essential for authorization workflows.
Users can update to Decidim versions 0.30.9, 0.31.5, or 0.32.0.rc2, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 6, 2026CISA-ADP
Assessed Aug 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/decidim/decidim/security/advisories/GHSA-q79h-67vx-m9xg | CISA-ADP | AdvisoryRemedyVendor |
| https://github.com/decidim/decidim/pull/16674 | [email protected] | Issue TrackingVendor |
| https://github.com/decidim/decidim/pull/16703 | [email protected] | Issue TrackingVendor |
| https://github.com/decidim/decidim/security/advisories/GHSA-q79h-67vx-m9xg | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Decidim | < 0.30.9 (semver) >= 0.31.0, < 0.31.5 (semver) >= 0.32.0.rc1, < 0.32.0.rc2 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 7, 2026 | CVE Modified | CISA-ADP |
| Aug 6, 2026 | New CVE Received | [email protected] |
Volerion