Security Advisory

CVE-2026-45086

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-31 21:44:11
Last updated 2026-08-03 17:16:23
Assigner GitHub_M
CVSS score not scored
State PUBLISHED

Description

Decidim is a participatory democracy framework. From 0.31.1 before 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, a participant can directly load /admin/demographics/questions/edit_questions and reach the demographics questionnaire editor without the required administrator authorization. The demographics questionnaire editor should require admin access, but the route under /admin/demographics/questions renders the editor interface without checking whether the caller is an admin. A normal participant can load the page and see the live update form action, which proves the protected interface is reachable. This issue is fixed in versions 0.31.5 and 0.32.0.rc2.