CVE-2026-23891 is a stored code execution vulnerability in Decidim, an open-source participatory democracy platform, affecting versions below 0.30.5 and 0.31.0.rc1 through 0.31.1. The flaw exists in the user name field and allows low-privileged attackers to inject and execute arbitrary code that runs in the context of any user who views affected comment pages, compromising both confidentiality and integrity across security boundaries. The vulnerability has been patched in versions 0.30.5 and 0.31.1. The attack requires network access with low privilege credentials and user interaction, as victims must passively visit a compromised comment page for exploitation. The CVSS 3.1 score of 8.7 reflects the high severity due to significant confidentiality and integrity impacts, though availability is not affected. An attacker can steal sensitive information or modify content visible to legitimate users without requiring complex technical conditions. There is currently no active exploitation detected in the wild, and this vulnerability is not included on CISA's Known Exploited Vulnerabilities catalog. The EPSS score of 0.00046 indicates minimal real-world exploitation likelihood compared to other CVEs, and the vulnerability has not generated substantial community attention or readily available exploit code, suggesting a measured rather than critical threat posture at present.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.30.5CPE matchmatch criteria | cpe:2.3:a:decidim:decidim:*:*:*:*:*:ruby:*:* | ||
>= 0.31.0, < 0.31.1CPE matchmatch criteria | cpe:2.3:a:decidim:decidim:*:*:*:*:*:ruby:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.