CVE-2026-45414

Source
https://cve.org/CVERecord?id=CVE-2026-45414
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45414.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-45414
Aliases
Published
2026-08-06T19:17:17.988Z
Modified
2026-08-09T03:30:43.027183852Z
Severity
  • 8.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N CVSS Calculator
Summary
Decidim: JWT-backed authentication can be replayed across organizations
Details

Decidim is a participatory democracy framework. Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, JWT-backed API authentication is not bound to the organization selected by the current host, allowing a JWT issued for one tenant to be replayed against another tenant’s API to read participantDetails data and reach the proposal.answer mutation path. This issue is fixed in versions 0.31.5 and 0.32.0.rc2.

Database specific
{
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45414.json",
    "cwe_ids": [
        "CWE-639",
        "CWE-863"
    ]
}
References

Affected packages

Git / github.com/decidim/decidim

Affected ranges

Type
GIT
Repo
https://github.com/decidim/decidim
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0.32.0.rc1"
        },
        {
            "fixed": "0.32.0.rc2"
        }
    ],
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

v0.*
v0.32.0.rc1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45414.json"