PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-45415 decidim CVE debrief

The Decidim framework, used for participatory democracy, has a critical vulnerability in its /admin/csv_census/census_logs record-management endpoints. This issue, identified as CVE-2026-45415, allows participant managers to create, alter, or remove census records without proper authorization. The vulnerability affects Decidim versions prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2. This could lead to unauthorized data tampering and modifications to census records. Users and administrators of Decidim should be aware of this vulnerability and take immediate action to secure their systems.

Vendor
decidim
Product
Unknown
CVSS
MEDIUM 6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-06
Original CVE updated
2026-08-07
Advisory published
2026-08-06
Advisory updated
2026-08-07

Who should care

Decidim users and administrators, security teams responsible for participatory democracy frameworks, and operators of systems using Decidim for census management should prioritize patching and securing their systems to prevent unauthorized data modifications and potential security breaches. This includes reviewing system configurations, ensuring proper authorization is enforced, and monitoring for suspicious activities related to census record management. Security teams should also verify that all participant managers and administrators are aware of this vulnerability and take necessary precautions to protect their systems and data. Additionally, organizations using Decidim should consider implementing compensating controls, such as restricting access to census management endpoints and enhancing monitoring and detection capabilities, while remediation is scheduled and verified. It is also essential to track exceptions, retest remediated assets, and close the item only after evidence is documented to ensure the vulnerability is fully addressed. By taking these steps, Decidim users and administrators can help prevent potential security breaches and protect their systems and data from unauthorized access and modifications. Furthermore, it is crucial to review and update incident response plans to include procedures for responding to potential security breaches related to this vulnerability. By prioritizing patching and taking proactive measures, Decidim users and administrators can minimize the risk of security breaches and ensure the integrity of their systems and data. Security teams should also consider conducting regular security audits and penetration testing to identify and address potential vulnerabilities before they can be exploited. By taking a proactive and comprehensive approach to security, Decidim users and administrators can help protect their systems and data from potential security threats. The CVE record was published on 2026-08-06T22:17:07.020Z and has not been modified since then. The NVD detail page for CVE-2026-45415 provides additional information on this vulnerability, including its CVSS score and severity. Users and administrators should be

Technical summary

The Decidim framework has a vulnerability in its /admin/csv_census/census_logs record-management endpoints. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, these endpoints do not enforce full administrator authorization before rendering or mutating Decidim::Verifications::CsvDatum. This allows a participant manager to create, alter, or remove census records. The issue is fixed in versions 0.30.9, 0.31.5, and 0.32.0.rc2. Users should apply patches or updates to Decidim to prevent potential data tampering and unauthorized census record modifications.

Defensive priority

Decidim users should prioritize patching to prevent potential data tampering and unauthorized census record modifications.

Recommended defensive actions

  • Apply patches or updates to Decidim versions 0.30.9, 0.31.5, or 0.32.0.rc2
  • Restrict access to /admin/csv_census/census_logs endpoints
  • Monitor for suspicious census record modifications
  • Verify administrator authorization for census management tasks
  • Review system configurations to ensure proper authorization is enforced
  • Enhance monitoring and detection capabilities for census record management
  • Track exceptions and retest remediated assets to ensure the vulnerability is fully addressed

Evidence notes

The Decidim framework has a vulnerability in its /admin/csv_census/census_logs endpoints, allowing participant managers to create, alter, or remove census records without full administrator authorization. This issue is fixed in versions 0.30.9, 0.31.5, and 0.32.0.rc2. Evidence is based on official CVE and NVD records, as well as GitHub security advisories.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:17:07.020Z and has not been modified since then.