<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 05:10:52 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-343791</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-343791</link>
      <description>EUVD-2026-343791</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-343791</guid>
    </item>
    <item>
      <title>fkie_cve-2026-45086</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45086</link>
      <description>&lt;p&gt;Decidim is a participatory democracy framework. From 0.31.1 before 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, a participant can directly load /admin/demographics/questions/edit_questions and reach the demographics questionnaire editor without the required administrator authorization. The demographics questionnaire editor should require admin access, but the route under /admin/demographics/questions renders the editor interface without checking whether the caller is an admin. A normal participant can load the page and see the live update form action, which proves the protected interface is reachable. This issue is fixed in versions 0.31.5 and 0.32.0.rc2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Decidim is a participatory democracy framework. From 0.31.1 before 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, a participant can directly load /admin/demographics/questions/edit_questions and reach the demographics questionnaire editor without the required administrator authorization. The demographics questionnaire editor should require admin access, but the route under /admin/demographics/questions renders the editor interface without checking whether the caller is an admin. A normal participant can load the page and see the live update form action, which proves the protected interface is reachable. This issue is fixed in versions 0.31.5 and 0.32.0.rc2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-45086</guid>
    </item>
    <item>
      <title>GHSA-vq6j-hj8w-7v39 — Decidim: Forms admin question editor lacks authorization</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vq6j-hj8w-7v39</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: decidim-demographics&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;A participant can load the demographics questionnaire admin editor and make changes.&lt;/p&gt;
&lt;p&gt;## Technical description&lt;/p&gt;
&lt;p&gt;The demographics questionnaire editor should require admin access, but the route under `/admin/demographics/questions` renders the editor interface without checking whether the caller is an admin. A normal participant can load the page and see the live update form action, which proves the protected interface is reachable.&lt;/p&gt;
&lt;p&gt;Reproduction steps:&lt;/p&gt;
&lt;p&gt;Step 1. Sign in as a normal participant: Open `http://localhost:3000/users/sign_in`.
Step 2. Request the admin-only editor directly. Open `http://localhost:3000/admin/demographics/questions/edit_questions` in the same browser.
Step 3. Add another question:&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;1522&amp;#34; height=&amp;#34;1174&amp;#34; alt=&amp;#34;decidim-questions-01&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/923f85d4-0e2f-4511-a9f3-a92f74dbf1d8&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;Note that access was denied when attempting to see question responses or settings.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;- Low-privilege users can access questionnaire-admin interfaces.
- They can read question-management surfaces that should remain limited to questionnaire managers.
 
### Patches&lt;/p&gt;
&lt;p&gt;See https://github.com/decidim/decidim/pull/16665&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Disable the &amp;#34;decidim-demographics&amp;#34; module&lt;/p&gt;
&lt;p&gt;### Reference&lt;/p&gt;
&lt;p&gt;OWASP A01:2021 Broken Access Control&lt;/p&gt;
&lt;p&gt;### Credits&lt;/p&gt;
&lt;p&gt;This issue was discovered in a security audit organized by the [Decidim Association](https://decidim.org) and made by [Radically Open Security](https://www.radicall…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: decidim-demographics&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;A participant can load the demographics questionnaire admin editor and make changes.&lt;/p&gt;
&lt;p&gt;## Technical description&lt;/p&gt;
&lt;p&gt;The demographics questionnaire editor should require admin access, but the route under `/admin/demographics/questions` renders the editor interface without checking whether the caller is an admin. A normal participant can load the page and see the live update form action, which proves the protected interface is reachable.&lt;/p&gt;
&lt;p&gt;Reproduction steps:&lt;/p&gt;
&lt;p&gt;Step 1. Sign in as a normal participant: Open `http://localhost:3000/users/sign_in`.
Step 2. Request the admin-only editor directly. Open `http://localhost:3000/admin/demographics/questions/edit_questions` in the same browser.
Step 3. Add another question:&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;1522&amp;#34; height=&amp;#34;1174&amp;#34; alt=&amp;#34;decidim-questions-01&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/923f85d4-0e2f-4511-a9f3-a92f74dbf1d8&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;Note that access was denied when attempting to see question responses or settings.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;- Low-privilege users can access questionnaire-admin interfaces.
- They can read question-management surfaces that should remain limited to questionnaire managers.
 
### Patches&lt;/p&gt;
&lt;p&gt;See https://github.com/decidim/decidim/pull/16665&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Disable the &amp;#34;decidim-demographics&amp;#34; module&lt;/p&gt;
&lt;p&gt;### Reference&lt;/p&gt;
&lt;p&gt;OWASP A01:2021 Broken Access Control&lt;/p&gt;
&lt;p&gt;### Credits&lt;/p&gt;
&lt;p&gt;This issue was discovered in a security audit organized by the [Decidim Association](https://decidim.org) and made by [Radically Open Security](https://www.radicall…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vq6j-hj8w-7v39</guid>
    </item>
  </channel>
</rss>
