CVE-2026-45414 (decidim): Decidim - JWT-backed authentication can be replayed across organizations
21-Jul-2026 2
Originally appeared on RubySec.## Description A JWT issued to an Org 1 account is accepted on the Org 2 API and can read the admin-only GraphQL `participantDetails` field for an Org 2 participant. The same trust-boundary problem also affects API-user authentication: an Org 1 A...
CVE-2026-45414 (decidim): Decidim - JWT-backed authentication can be replayed across organizations #ruby #rubydeveloper #rubyonrails #ruby #rubyonrails #programming #webdev #cve-2026-45414 #(decidim): #authentication https://www.rubyonrails.ba/link/cve-2026-45414-decidim-decidim-jwt-backed-authentication-can-be-replayed-across-organizations