Description
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the /admin/csv_census/census_logs record-management endpoints do not enforce full administrator authorization before rendering or mutating Decidim::Verifications::CsvDatum, allowing a participant manager to create, alter, or remove census records. This issue is fixed in versions 0.30.9, 0.31.5, and 0.32.0.rc2.
Published: 2026-08-06
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Decidim is a participatory democracy framework. A vulnerability in the /admin/csv_census/census_logs record‑management endpoints allows a user with the participant manager role to create, modify, or delete Decidim::Verifications::CsvDatum records without proper administrator authorization, resulting in unauthorized data manipulation and potential exposure of demographic information.

Affected Systems

The flaw exists in Decidim releases prior to 0.30.9, from 0.31.0 up to but excluding 0.31.5, and in 0.32.0.rc1 up until but excluding 0.32.0.rc2. Administrators using those versions are affected.

Risk and Exploitability

The CVSS score is 6, indicating moderate severity. The EPSS score is not available and the issue is not listed in the CISA KEV catalog. Because the flaw requires only a participant manager role, an attacker who can elevate privileges or obtain a participant manager account can exploit the endpoints via HTTP requests, representing a moderate risk for unpatched Decidim deployments.

Generated by OpenCVE AI on August 7, 2026 at 01:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Decidim to version 0.30.9, 0.31.5, 0.32.0.rc2, or a later release that includes the fix.
  • If an immediate upgrade is not possible, restrict access to the /admin/csv_census/census_logs endpoints by configuring the web server or application firewall to allow only top‑level administrators, removing participant manager access.
  • As an interim protection, invalidate or rotate any credentials or tokens belonging to participant manager accounts until the vulnerability is remediated, to prevent exploitation.

Generated by OpenCVE AI on August 7, 2026 at 01:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-q79h-67vx-m9xg Decidim: CSV census record endpoints improper authorization
History

Fri, 07 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Decidim
Decidim decidim
Vendors & Products Decidim
Decidim decidim

Thu, 06 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the /admin/csv_census/census_logs record-management endpoints do not enforce full administrator authorization before rendering or mutating Decidim::Verifications::CsvDatum, allowing a participant manager to create, alter, or remove census records. This issue is fixed in versions 0.30.9, 0.31.5, and 0.32.0.rc2.
Title Decidim: CSV census record endpoints improper authorization
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-07T15:45:33.809Z

Reserved: 2026-05-12T01:48:40.452Z

Link: CVE-2026-45415

cve-icon Vulnrichment

Updated: 2026-08-07T15:45:07.687Z

cve-icon NVD

Status : Received

Published: 2026-08-06T22:17:07.020

Modified: 2026-08-07T16:17:24.533

Link: CVE-2026-45415

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T01:15:05Z

Weaknesses