PatchSiren cyber security CVE debrief
CVE-2026-45330 decidim CVE debrief
The Decidim framework, a participatory democracy platform, has a vulnerability (CVE-2026-45330) that allows administrators from one tenant to access and manage ID-document requests from another tenant. This issue arises from the lack of proper current_organization ownership verification in the identity-document verification admin controllers. The vulnerability has a CVSS score of 4.9 and is classified as medium severity. Affected product deployments should be identified in managed environments, and owners should be assigned for follow-up. The official CVE record and NVD detail should be reviewed to validate affected scope, severity, and vendor guidance.
- Vendor
- decidim
- Product
- Unknown
- CVSS
- MEDIUM 4.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-31
- Original CVE updated
- 2026-07-31
- Advisory published
- 2026-07-31
- Advisory updated
- 2026-07-31
Who should care
Administrators and users of Decidim instances, especially those with multiple tenants, should be aware of this vulnerability and take necessary actions to protect their systems. Affected operators, platform administrators, vulnerability management teams, and security teams should review the vulnerability and implement necessary mitigations. This includes verifying and applying available updates, reviewing compensating controls for exposed systems, and monitoring for suspicious activity related to ID-document requests. Additionally, asset inventory and rollback/change windows should be reviewed to ensure that exposed assets are properly managed and remediated. Source tracking and exposure review should also be conducted to ensure that the vulnerability is properly addressed. Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Check relevant monitoring, detection, and logs for exposed assets that need extra review. Track exceptions, retest remediated assets, and close the item only after evidence is documented. Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. The Decidim framework's vulnerability management and security teams should prioritize this issue and implement necessary mitigations to prevent potential identity-document verification abuse. Compensating controls for exposed systems should be reviewed and implemented while remediation is scheduled and verified. Monitoring and detection capabilities should be reviewed to ensure that exposed assets are properly managed and remediated. Asset inventory and rollback/change windows should be reviewed to ensure that exposed assets are properly managed and remediated. Source tracking and exposure review should be conducted to ensure that the vulnerability is properly addressed. The vulnerability management team should review the vulnerability and implement necessary mitigations to prevent potential identity-document verification abuse. The security team should review the vulnerability and ensure
Technical summary
The Decidim framework has a vulnerability (CVE-2026-45330) where administrators from one tenant can access and manage ID-document requests from another tenant. This issue arises from the lack of proper current_organization ownership verification in the identity-document verification admin controllers. The vulnerability has a CVSS score of 4.9 and is classified as medium severity. To address this vulnerability, administrators of Decidim instances should verify and apply available updates to prevent potential identity-document verification abuse. This can be achieved by applying updates to Decidim instances, verifying current_organization ownership for identity-document verification admin controllers, and monitoring for suspicious activity related to ID-document requests.
Defensive priority
Administrators of Decidim instances should verify and apply available updates to prevent potential identity-document verification abuse.
Recommended defensive actions
- Apply updates to Decidim instances to prevent potential identity-document verification abuse
- Verify current_organization ownership for identity-document verification admin controllers
- Monitor for suspicious activity related to ID-document requests
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record indicates a medium-severity vulnerability in Decidim, a participatory democracy framework. The issue allows administrators from one tenant to view, approve, or reject another tenant's ID-document request due to improper verification of current_organization ownership. This problem is fixed in versions 0.30.9, 0.31.5, and 0.32.0.rc2.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-31T23:17:24.233Z and has not been modified since then.