{"api_version":"1","generated_at":"2026-08-08T07:34:19+00:00","cve":"CVE-2026-45414","urls":{"html":"https://cve.report/CVE-2026-45414","api":"https://cve.report/api/cve/CVE-2026-45414.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-45414","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-45414"},"summary":{"title":"Decidim: JWT-backed authentication can be replayed across organizations","description":"Decidim is a participatory democracy framework. Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, JWT-backed API authentication is not bound to the organization selected by the current host, allowing a JWT issued for one tenant to be replayed against another tenant’s API to read participantDetails data and reach the proposal.answer mutation path. This issue is fixed in versions 0.31.5 and 0.32.0.rc2.","state":"PUBLISHED","assigner":"GitHub_M","published_at":"2026-08-06 22:17:06","updated_at":"2026-08-07 18:17:15"},"problem_types":["CWE-639","CWE-863","CWE-639 CWE-639: Authorization Bypass Through User-Controlled Key","CWE-863 CWE-863: Incorrect Authorization"],"metrics":[{"version":"3.1","source":"security-advisories@github.com","type":"Secondary","score":"8.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N","baseScore":8.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"8.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":8.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N","version":"3.1"}}],"references":[{"url":"https://github.com/decidim/decidim/commit/226dc94894e6a3c030e4638c8b3441ee7199643c","name":"https://github.com/decidim/decidim/commit/226dc94894e6a3c030e4638c8b3441ee7199643c","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/decidim/decidim/releases/tag/v0.32.0.rc2","name":"https://github.com/decidim/decidim/releases/tag/v0.32.0.rc2","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/decidim/decidim/commit/023e206127c984a501345676e4789b31ddd115a1","name":"https://github.com/decidim/decidim/commit/023e206127c984a501345676e4789b31ddd115a1","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/decidim/decidim/releases/tag/v0.31.5","name":"https://github.com/decidim/decidim/releases/tag/v0.31.5","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/decidim/decidim/security/advisories/GHSA-r3v7-5x4c-c69q","name":"https://github.com/decidim/decidim/security/advisories/GHSA-r3v7-5x4c-c69q","refsource":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-45414","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45414","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"decidim","product":"decidim","version":"affected < 0.31.5","platforms":[]},{"source":"CNA","vendor":"decidim","product":"decidim","version":"affected >= 0.32.0.rc1, < 0.32.0.rc2","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"45414","cve":"CVE-2026-45414","epss":"0.003240000","percentile":"0.248410000","score_date":"2026-08-07","updated_at":"2026-08-08 00:14:55"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-45414","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-08-07T17:50:28.456696Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-08-07T17:50:53.738Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"references":[{"tags":["exploit"],"url":"https://github.com/decidim/decidim/security/advisories/GHSA-r3v7-5x4c-c69q"}],"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"product":"decidim","vendor":"decidim","versions":[{"status":"affected","version":"< 0.31.5"},{"status":"affected","version":">= 0.32.0.rc1, < 0.32.0.rc2"}]}],"descriptions":[{"lang":"en","value":"Decidim is a participatory democracy framework. Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, JWT-backed API authentication is not bound to the organization selected by the current host, allowing a JWT issued for one tenant to be replayed against another tenant’s API to read participantDetails data and reach the proposal.answer mutation path. This issue is fixed in versions 0.31.5 and 0.32.0.rc2."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":8.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-639","description":"CWE-639: Authorization Bypass Through User-Controlled Key","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-863","description":"CWE-863: Incorrect Authorization","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-06T19:17:17.988Z","orgId":"a0819718-46f1-4df5-94e2-005712e83aaa","shortName":"GitHub_M"},"references":[{"name":"https://github.com/decidim/decidim/security/advisories/GHSA-r3v7-5x4c-c69q","tags":["x_refsource_CONFIRM"],"url":"https://github.com/decidim/decidim/security/advisories/GHSA-r3v7-5x4c-c69q"},{"name":"https://github.com/decidim/decidim/commit/023e206127c984a501345676e4789b31ddd115a1","tags":["x_refsource_MISC"],"url":"https://github.com/decidim/decidim/commit/023e206127c984a501345676e4789b31ddd115a1"},{"name":"https://github.com/decidim/decidim/commit/226dc94894e6a3c030e4638c8b3441ee7199643c","tags":["x_refsource_MISC"],"url":"https://github.com/decidim/decidim/commit/226dc94894e6a3c030e4638c8b3441ee7199643c"},{"name":"https://github.com/decidim/decidim/releases/tag/v0.31.5","tags":["x_refsource_MISC"],"url":"https://github.com/decidim/decidim/releases/tag/v0.31.5"},{"name":"https://github.com/decidim/decidim/releases/tag/v0.32.0.rc2","tags":["x_refsource_MISC"],"url":"https://github.com/decidim/decidim/releases/tag/v0.32.0.rc2"}],"source":{"advisory":"GHSA-r3v7-5x4c-c69q","discovery":"UNKNOWN"},"title":"Decidim: JWT-backed authentication can be replayed across organizations"}},"cveMetadata":{"assignerOrgId":"a0819718-46f1-4df5-94e2-005712e83aaa","assignerShortName":"GitHub_M","cveId":"CVE-2026-45414","datePublished":"2026-08-06T19:17:17.988Z","dateReserved":"2026-05-12T01:48:40.452Z","dateUpdated":"2026-08-07T17:50:53.738Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-06 22:17:06","lastModifiedDate":"2026-08-07 18:17:15","problem_types":["CWE-639","CWE-863","CWE-639 CWE-639: Authorization Bypass Through User-Controlled Key","CWE-863 CWE-863: Incorrect Authorization"],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N","baseScore":8.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":4.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-07T17:50:28.456696Z","id":"CVE-2026-45414","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"45414","Ordinal":"1","Title":"Decidim: JWT-backed authentication can be replayed across organi","CVE":"CVE-2026-45414","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"45414","Ordinal":"1","NoteData":"Decidim is a participatory democracy framework. Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, JWT-backed API authentication is not bound to the organization selected by the current host, allowing a JWT issued for one tenant to be replayed against another tenant’s API to read participantDetails data and reach the proposal.answer mutation path. This issue is fixed in versions 0.31.5 and 0.32.0.rc2.","Type":"Description","Title":"Decidim: JWT-backed authentication can be replayed across organi"}]}}}