CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-45414

highCVSS 8.5covered by 1 sourcefirst seen 2026-07-13
Description A JWT issued to an Org 1 account is accepted on the Org 2 API and can read the admin-only GraphQL participantDetails field for an Org 2 participant. The same trust-boundary problem also affects API-user authentication: an Org 1 API user can use a JWT on the Org 1 host and replay that JWT to the Org 2 API to read Org 2 participant personal data and reach Org 2's proposal.answer mutation path. Technical description The current host selects the Decidim organization context, but JWT-backed API authentication is not sufficiently bound to that host organization. As a result, the API can process a request in Org 2's context while still trusting an authenticated principal from Org 1. Reproduction steps: 1. Use an API key provided by the system administrator that is assigned to organization 1 to create the JWT token or get the JWT token shown in the response when logged in as the organization admin. <img width="1080" height="1119" alt="decidim-jwt-01" src="https://github.com/user-attachments/assets/6195a250-faef-41d5-8f64-4d77d4077e96" /> 2. When using this JWT token it is possible to retrieve details from other organisations. Notice the change of the host header in the request below to that of another tenant org2.localhost:3001 <img width="1085" height="1047" alt="decidim-jwt-02" src="https://github.com/user-attachments/assets/d40825e3-0d36-44f3-bede-86d247bbe6d0" /> Note that using a participant-generated JWT did not allow showing these results. Impact A JWT issued for one organization can be replayed successfully against another organization's API and used to retrieve sensitive details from that organization. Patches See https://github.com/decidim/decidim/pull/16673 and https://github.com/decidim/decidim/pull/16756 Workarounds Disable JWT credentials on system panel (/system) References OWASP A01:2021 Broken Access Control Credits This issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Se

⚡ Watch CVE-2026-45414

Get an email if CVE-2026-45414 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-45414

CVE.org record

Embed the live status

CVE-2026-45414 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-45414 status](https://www.csirts.com/badge/CVE-2026-45414)](https://www.csirts.com/cve/CVE-2026-45414)