CVE-2026-40869

7.5

Decidim · Decidim

A vulnerability in the Decidim framework allows authenticated users to improperly modify proposal amendments and gain unauthorized coauthorship status on existing resources.

Executive summary

A critical authorization flaw in the Decidim framework allows authenticated users to hijack proposal amendment workflows and claim unauthorized authorship.

Vulnerability

The vulnerability, classified as Incorrect Privilege Assignment (CWE-266), allows any registered and authenticated user to accept or reject amendments to proposals they did not create. This process improperly grants the malicious actor coauthorship rights on the original proposal resources.

Business impact

Successful exploitation compromises the integrity of the participatory democracy process by allowing unauthorized users to manipulate proposal outcomes and falsely associate themselves as authors. With a CVSS score of 7.5, this high-severity flaw poses a significant risk to the credibility and administrative control of platforms utilizing the Decidim framework.

Remediation

Immediate Action: Upgrade to Decidim versions 0.30.5 or 0.31.1 to resolve the authorization logic error.

Proactive Monitoring: Review application audit logs for suspicious amendment acceptance or rejection patterns, specifically focusing on users gaining unexpected coauthorship rights on proposals.

Compensating Controls: If an immediate upgrade is not feasible, disable the amendment reactions feature for all amendable components, such as proposals, to prevent unauthorized interaction.

Exploitation status

Public Exploit Available: No (exploit_available unknown)

Analyst recommendation

This vulnerability represents a significant threat to the integrity of platform data and user attribution. Administrators should prioritize the deployment of the provided patches in versions 0.30.5 or 0.31.1 to restore proper authorization controls and prevent unauthorized modifications to proposal resources.

More Decidim CVEs

Sources