CVE-2026-40870Disclosure

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Decidim is a participatory democracy framework. Starting in version 0.0.1 and prior to versions 0.30.5 and 0.31.1, the root level `commentable` field in the API allows access to all commentable resources within the platform, without any permission checks. All Decidim instances are impacted that have not secured the `/api` endpoint. The `/api` endpoint is publicly available with the default configuration. Versions 0.30.5 and 0.31.1 fix the issue. As a workaround, limit the scope to only authenticated users by limiting access to the `/api` endpoint. This would require custom code or installing the 3rd party module `Decidim::Apiauth`. With custom code, the `/api` endpoint can be limited to only authenticated users. The same configuration can be also used without the `allow` statements to disable all traffic to the the `/api` endpoint. When considering a workaround and the seriousness of the vulnerability, please consider the nature of the platform. If the platform is primarily serving public data, this vulnerability is not serious by its nature. If the platform is protecting some resources, e.g. inside private participation spaces, the vulnerability may expose some data to the attacker that is not meant public. For those who have enabled the organization setting "Force users to authenticate before access organization", the scope of this vulnerability is limited to the users who are allowed to log in to the Decidim platform. This setting was introduced in version 0.19.0 and it was applied to the `/api` endpoint in version 0.22.0.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC and exploit tooling are both present
  • 2 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-22: 2PoC Mentioned / Linked · 2026-04-22: 1Exploit Tool / Code · 2026-04-22: 1Technical Details · 2026-04-22: 204-22
Signal classification2 categories
Disclosure
150.0%
PoC
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • CypherByte@cypherbyteio
    PoC

    Digital democracy has a massive blind spot. 🗳️🔓 A critical Authorization Bypass (CVE-2026-40870) has been discovered in Decidim, the open-source platform for citizen participation. By exploiting the GraphQL API, attackers can manipulate comments and silence discussions they shouldn't even have access to. When the tools of participation are compromised, the integrity of the vote is at risk. 🛡️ Full Technical PoC: https://www.cypherbyte.io/blog/cve-2026-40870-decidim-graphql-commentable-authz-bypass/ The exploits don't stop. Don't be the last to know. Follow Cypherbyte for real-time alerts. 🛡️ #Decidim #GraphQL #BugBounty #CyberSecurity #Infosec #CVE2026 #ZeroDay

    Post summary

    A full PoC for an Authorization Bypass (CVE‑2026‑40870) in Decidim’s GraphQL API was published, demonstrating comment manipulation, but there is no evidence of active exploitation or a vendor patch.

    0000047
    6 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40870 Unauthorized API Access to Commentable Resources in Decidim Below 0.30.5 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40870

    Post summary

    The text lists CVE‑2026‑40870, describing an unauthorized API access vulnerability in Decidim versions below 0.30.5, and links to a vulnerability detail page.

    0000041
    4.0K followersView on X

Explore more