CVE-2026-45376
Decidim: Admin user search allows SQL injection through similarity-based sorting
CVSS Score
5.5
EPSS Score
0.3%
EPSS Percentile
27th
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the GET /admin/organization/users search interpolates params[:term] into raw Arel.sql ORDER BY similarity expressions before sanitization, allowing an authenticated organization administrator to execute blind PostgreSQL expressions and infer data through timing differences. This issue is fixed in versions 0.30.9, 0.31.5, and 0.32.0.rc2.
| Vendor | decidim |
| Product | decidim |
| Published | Jul 31, 2026 |
| Last Updated | Aug 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for decidim decidim
Be the first to know when new medium vulnerabilities affecting decidim decidim are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup