
Digital democracy has a massive blind spot. 🗳️🔓 A critical Authorization Bypass (CVE-2026-40870) has been discovered in Decidim, the open-source platform for citizen participation. By exploiting the GraphQL API, attackers can manipulate comments and silence discussions they shouldn't even have access to. When the tools of participation are compromised, the integrity of the vote is at risk. 🛡️ Full Technical PoC: https://www.cypherbyte.io/blog/cve-2026-40870-decidim-graphql-commentable-authz-bypass/ The exploits don't stop. Don't be the last to know. Follow Cypherbyte for real-time alerts. 🛡️ #Decidim #GraphQL #BugBounty #CyberSecurity #Infosec #CVE2026 #ZeroDay
Post summary
A full PoC for an Authorization Bypass (CVE‑2026‑40870) in Decidim’s GraphQL API was published, demonstrating comment manipulation, but there is no evidence of active exploitation or a vendor patch.

