What is CVE-2026-45330?
CVE-2026-45330 is a security vulnerability in Decidim, a participatory democracy framework, where identity-document verification admin controllers load pending Authorization records by raw identifier without confirming current_organization ownership. This affects versions prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2. Users should upgrade to the patched versions immediately.
Azərbaycanca: CVE-2026-45330, açıq demokratiya çərçivəsi olan Decidim-də identiklik sənədi yoxlama admin controller-lərində təhlükəsizlik zəifliyidir. Zəiflik, təşkilat sahibliyi yoxlanılmadan xam identifikatorla gözləyən Authorization qeydlərinin yüklənməsi səbəbindən baş verir. Təsirə məruz qalmış versiyaları istifadə edən təşkilatlar dərhal göstərilən versiyalara (0.30.9, 0.31.5, 0.32.0.rc2) yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What functionality in the Decidim platform is affected by CVE-2026-45330?
This vulnerability affects the identity-document verification admin controllers. Pending Authorization records are loaded by raw identifier without confirming current_organization ownership.
What patched versions should be upgraded to for CVE-2026-45330?
Affected organizations should immediately upgrade to versions 0.30.9, 0.31.5, or 0.32.0.rc2.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.