CVE-2026-45414
Decidim is a participatory democracy framework. Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, JWT-backed API authentication is not bound to the organization selected by the current host, allowing a JWT issued for one tenant to be replayed against another tenant’s API to read participantDetails data and reach the proposal.answer mutation path. This issue is fixed in versions 0.31.5 and 0.32.0.rc2.
- Affected products
- Decidim
- Fix
- Available
- CVSS 3.1
- 8.5 HIGH
- Weakness
- CWE-639, CWE-863
- NVD status
- Received
- Published
- 2026-08-06
CVE-2026-45414 at NVD
No indexed exploits for CVE-2026-45414 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-45414 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.