CVE-2026-45414

HIGH

Decidim: JWT-backed authentication can be replayed across organizations

Title source: cna
STIX 2.1

Description

Decidim is a participatory democracy framework. Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, JWT-backed API authentication is not bound to the organization selected by the current host, allowing a JWT issued for one tenant to be replayed against another tenant’s API to read participantDetails data and reach the proposal.answer mutation path. This issue is fixed in versions 0.31.5 and 0.32.0.rc2.

Scores

CVSS v3 8.5
EPSS 0.0032
EPSS Percentile 24.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-639 CWE-863
Status published
Products (2)
decidim/decidim < 0.31.5
decidim/decidim >= 0.32.0.rc1, < 0.32.0.rc2
Published Aug 06, 2026
Tracked Since Aug 07, 2026