๐Ÿ” CVE Alert

CVE-2026-42303

UNKNOWN 0.0

Fides: Privacy Request Identity Verification Bypass Vulnerability via Duplicate Detection

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Fides is an open-source privacy engineering platform. From 2.75.0 to before 2.83.2, Fides deployments that enable both subject identity verification and duplicate privacy request detection are affected by a vulnerability in which an administrator can approve a privacy request whose identity was never verified. For erasure policies, this can result in unauthorized deletion of a data subject's records across every integration configured in the affected deployment. This vulnerability is fixed in 2.83.2.

CWE CWE-288 CWE-306 CWE-841
Vendor ethyca
Product fides
Published May 12, 2026
Last Updated May 12, 2026
Stay Ahead of the Next One

Get instant alerts for ethyca fides

Be the first to know when new unknown vulnerabilities affecting ethyca fides are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

ethyca / fides
>= 2.75.0, < 2.83.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/ethyca/fides/security/advisories/GHSA-qx5f-ghc2-7g5c github.com: https://github.com/ethyca/fides/pull/7971 github.com: https://github.com/ethyca/fides/pull/7972 github.com: https://github.com/ethyca/fides/commit/0e320b20934eb5af3a3d5127dba2691605d7ff37 github.com: https://github.com/ethyca/fides/commit/e7a6527b0f9fdc9887b86a89bb5453e7421882dd github.com: https://github.com/ethyca/fides/releases/tag/2.83.2