What is CVE-2026-45086?
CVE-2026-45086 is a vulnerability in the Decidim participatory democracy framework. It allows an authenticated participant to bypass authorization and directly access the demographics questionnaire editor via `/admin/demographics/questions/edit_questions` without admin privileges. Upgrading to the patched versions is strongly recommended.
Azərbaycanca: CVE-2026-45086 Decidim iştirakçı demokratiya çərçivəsində aşkar edilmiş zəiflikdir. Bu boşluq autentifikasiya olunmuş adi iştirakçıya `/admin/demographics/questions/edit_questions` səhifəsinə birbaşa daxil olaraq inzibati səlahiyyət tələb edən demoqrafik sorğu redaktoruna icazəsiz giriş imkanı verir. Təsirə məruz qalan versiyalardan təhlükəsiz versiyalara təcili yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Does an attacker need to be authenticated in the Decidim system to exploit CVE-2026-45086?
Yes, this vulnerability can only be exploited by an authenticated participant.
What is the specific URL that can be accessed without authorization via CVE-2026-45086?
The vulnerability allows direct access to the demographics questionnaire editor via `/admin/demographics/questions/edit_questions`.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.