Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4355 articles · 196337 vulns · 36/41 feeds (7d)
← Back to list
6.0
CVE-2026-45415PATCHED
rubygems · decidim-verifications

Decidim: CSV census record endpoints improper authorization

Description

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the /admin/csv_census/census_logs record-management endpoints do not enforce full administrator authorization before rendering or mutating Decidim::Verifications::CsvDatum, allowing a participant manager to create, alter, or remove census records. This issue is fixed in versions 0.30.9, 0.31.5, and 0.32.0.rc2.

Affected Products

VendorProductVersions
rubygemsdecidim-verifications< 0.30.9, >= 0.31.0.rc1, < 0.31.5, >= 0.32.0.rc1, < 0.32.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
rubygemsdecidim-verificationsGHSA85%

References

  • https://github.com/decidim/decidim/security/advisories/GHSA-q79h-67vx-m9xg(x_refsource_CONFIRM)
  • https://github.com/decidim/decidim/pull/16674(x_refsource_MISC)
  • https://github.com/decidim/decidim/pull/16703(x_refsource_MISC)

Related News (1 articles)

Tier C
VulDB17d ago
CVE-2026-45415 | Decidim up to 0.30.8/0.31.4/0.32.0.rc1 Census Logs census_logs improper authorization
→ No new info (linked only)
CVSS 3.16.0 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:L
CISA KEV❌ No
Actively exploited❌ No
Patch available
decidim-verifications@0.30.9decidim-verifications@0.31.5decidim-verifications@0.32.0
CWECWE-862
PublishedJul 13, 2026
Tags
GHSA-q79h-67vx-m9xgrubygems
Trending Score4
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-66066
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
Trending: 61
NONECVE-2026-61666
websocket-driver: Denial of service via malformed Host header
Trending: 8
HIGHCVE-2026-45378
Decidim: Verification documents can be downloaded through reusable links
Trending: 7
NONECVE-2026-71847
Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams
Trending: 6
HIGHCVE-2026-45414
Decidim: JWT-backed authentication can be replayed across organizations
Trending: 5

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 13, 2026
Discovered by ZDM
Jul 13, 2026
Patch Available
Aug 7, 2026