← All reports

The Decidim framework has vulnerabilities that allow unauthorized users to manipulate amendments and access commentable resources.

CybersecurityTechnologyConflictParticipatory DemocracyApr 21, 2026score 0.172 posts · 0 replies across 1 instances
The thread discusses two high-severity vulnerabilities in the Decidim participatory democracy framework, affecting user permissions and API access. These vulnerabilities highlight security risks in open-source platforms used for democratic processes.

Claims

The Decidim framework has vulnerabilities that allow unauthorized users to manipulate amendments and access commentable resources.
Parent: CybersecurityEntity: Decidim frameworkImpact: negativeDate: Apr 21, 2026Target: The Decidim framework's security measures

Source posts

@[email protected]
🟠 CVE-2026-40870 - High (7.5) Decidim is a participatory democracy framework. Starting in version 0.0.1 and prior to versions 0.30.5 and 0.31.1, the root level `commentable` field in the API allows access to all commentable resources within the platform, without any permission... 🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-40870/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
0 boosts · 0 favs · 0 replies · Apr 21, 2026
#cve#vulnerability#infosec#cybersecurity#security#tenda
@[email protected]
🟠 CVE-2026-40869 - High (7.5) Decidim is a participatory democracy framework. Starting in version 0.19.0 and prior to versions 0.30.5 and 0.31.1, a vulnerability allows any registered and authenticated user to accept or reject any amendments. The impact is on any users who hav... 🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-40869/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
0 boosts · 0 favs · 0 replies · Apr 21, 2026
#cve#vulnerability#infosec#cybersecurity#security#tenda