CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-45378

highCVSS 7.5covered by 1 sourcefirst seen 2026-07-13
Description Scanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed /rails/active_storage/disk/ URLs that can be fetched without any authenticated session. Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical description This issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with variant_url(...), which produces signed /rails/active_storage/disk/... links instead of routing the file through an authorization-checking controller. Because Decidim configures Active Storage service URLs to remain valid for seven days, the URL itself becomes the credential for that period. The affected files are verification_attachment blobs on Decidim::Authorization, and the admin review pages embed those signed URLs directly into the HTML for pending and confirmation views. Reproduction steps: 1. Create a fresh verification document as a normal user. 1.1. Open http://localhost:3001/users/sign_in. 1.2. Open http://localhost:3001/id_documents/authorizations/new. 1.3. Submit an id_documents verification request with an image attachment. 2. Open the admin review page that renders the attachment. 2.1. Sign out. 2.2. Sign back in as admin@example.org. 2.3. Try http://localhost:3001/admin/id_documents. 3. Harvest the signed Active Storage URL. 3.1. Open DevTools Network before loading the review page. 3.2. Reload the page. 3.3. Copy one request URL matching http://localhost:3001/rails/active_storage/disk/<SIGNED_TOKEN>/<FILENAME>. 4. Replay the file URL without any Decidim session. 4.1. Open a private window or a second browser where you are not signed in to Decidim. 4.2. Paste the exact copied /rails/active_storage/disk/... URL. 4.3. Confirm the verification image still loads. Impact - This only applies to Organizations using the "Identity documents" verif

⚡ Watch CVE-2026-45378

Get an email if CVE-2026-45378 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-45378

CVE.org record

Embed the live status

CVE-2026-45378 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-45378 status](https://www.csirts.com/badge/CVE-2026-45378)](https://www.csirts.com/cve/CVE-2026-45378)