What is CVE-2026-45376?
This vulnerability allows an authenticated organization admin in Decidim to perform SQL injection via the `params[:term]` parameter in the `/admin/organization/users` search, due to improper sanitization before interpolation into `Arel.sql` ORDER BY similarity expressions. Affected versions are prior to 0.30.9, from 0.31.0 before 0.31.5, and 0.32.0.rc1; users should upgrade to 0.30.9, 0.31.5, or 0.32.0.rc2 immediately.
Azərbaycanca: Bu zəiflik Decidim platformasında autentifikasiya olunmuş təşkilat adminlərinə `/admin/organization/users` axtarış sorğusunda `params[:term]` vasitəsilə SQL injeksiyası etməyə imkan verir. Təsirə məruz qalan versiyalar 0.30.9-dan əvvəl, 0.31.0-dan 0.31.5-ə qədər və 0.32.0.rc1-dir; istifadəçilər dərhal 0.30.9, 0.31.5 və ya 0.32.0.rc2 versiyalarına yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Who can exploit the SQL injection vulnerability CVE-2026-45376 on the Decidim platform?
This vulnerability can only be exploited by an authenticated organization admin in Decidim.
Which Decidim versions should be upgraded to in order to remediate CVE-2026-45376?
Users should immediately upgrade to versions 0.30.9, 0.31.5, or 0.32.0.rc2.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.