{"id":"GHSA-vq6j-hj8w-7v39","summary":"Decidim: Forms admin question editor lacks authorization","details":"## Description\n\nA participant can load the demographics questionnaire admin editor and make changes.\n\n## Technical description\n\nThe demographics questionnaire editor should require admin access, but the route under `/admin/demographics/questions` renders the editor interface without checking whether the caller is an admin. A normal participant can load the page and see the live update form action, which proves the protected interface is reachable.\n\nReproduction steps:\n\nStep 1. Sign in as a normal participant: Open `http://localhost:3000/users/sign_in`.\nStep 2. Request the admin-only editor directly. Open `http://localhost:3000/admin/demographics/questions/edit_questions` in the same browser.\nStep 3. Add another question:\n\n\u003cimg width=\"1522\" height=\"1174\" alt=\"decidim-questions-01\" src=\"https://github.com/user-attachments/assets/923f85d4-0e2f-4511-a9f3-a92f74dbf1d8\" /\u003e\n\nNote that access was denied when attempting to see question responses or settings.\n\n### Impact\n\n- Low-privilege users can access questionnaire-admin interfaces.\n- They can read question-management surfaces that should remain limited to questionnaire managers.\n \n### Patches\n\nSee https://github.com/decidim/decidim/pull/16665 \n\n### Workarounds\n\nDisable the \"decidim-demographics\" module \n\n### Reference\n\nOWASP A01:2021 Broken Access Control\n\n### Credits\n\nThis issue was discovered in a security audit organized by the [Decidim Association](https://decidim.org) and made by [Radically Open Security](https://www.radicallyopensecurity.com/) against Decidim financed by [NGI](https://ngi.eu/).","aliases":["CVE-2026-45086"],"modified":"2026-07-13T17:11:53.826837Z","published":"2026-07-13T16:51:05Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-07-13T16:51:05Z","nvd_published_at":null,"cwe_ids":["CWE-284"]},"references":[{"type":"WEB","url":"https://github.com/decidim/decidim/security/advisories/GHSA-vq6j-hj8w-7v39"},{"type":"WEB","url":"https://github.com/decidim/decidim/pull/16665"},{"type":"PACKAGE","url":"https://github.com/decidim/decidim"}],"affected":[{"package":{"name":"decidim-demographics","ecosystem":"RubyGems","purl":"pkg:gem/decidim-demographics"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.31.0"},{"fixed":"0.31.5"}]}],"versions":["0.31.0","0.31.1","0.31.2","0.31.3","0.31.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-vq6j-hj8w-7v39/GHSA-vq6j-hj8w-7v39.json"}},{"package":{"name":"decidim-demographics","ecosystem":"RubyGems","purl":"pkg:gem/decidim-demographics"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.32.0.rc1"},{"fixed":"0.32.0"}]}],"versions":["0.32.0.rc1","0.32.0.rc2","0.32.0.rc3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-vq6j-hj8w-7v39/GHSA-vq6j-hj8w-7v39.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"}]}