Executive brief
Decidim, a framework for participatory democracy, contains a flaw where any registered user can accept or reject proposed changes (amendments) to proposals. This allows unauthorized individuals to manipulate community proposals and potentially gain co-authorship rights over content they did not create. This could lead to misinformation, unauthorized modification of community initiatives, and damage to the integrity of the democratic process.
Technical details
An incorrect privilege assignment (CWE-266) in Decidim's permission logic allows any authenticated user to perform 'accept' or 'reject' actions on amendments. The root cause is located in `decidim-core/app/permissions/decidim/permissions.rb`, where the system only checks if amendment reactions are enabled for a component rather than verifying if the user has the authority to manage the specific amendment. Exploitation allows an attacker to modify the status of any amendment and gain co-authorship status on the associated resource. The issue was introduced in version 0.19.0 and is fixed in versions 0.30.5 and 0.31.1.
Affected products
- Decidim decidim-core >= 0.19.0, < 0.30.5; >= 0.31.0.rc1, < 0.31.1
Timeline
- 2019-06-17: other: Vulnerability introduced in commit 1b99136 (v0.19.0)
- 2026-04-13: disclosed
- 2026-04-14: advisory
- 2026-04-21: other: NVD published CVE-2026-40869
References
- https://github.com/decidim/decidim/security/advisories/GHSA-w5xj-99cg-rccm
- https://github.com/decidim/decidim/commit/1b99136a1c7aa02616a0b54a6ab88d12907a57a9
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/decidim-core/CVE-2026-40869.yml
- https://api.github.com/repos/decidim/decidim/security-advisories/GHSA-w5xj-99cg-rccm