Threat Advisory

Decidim Elections Flaw Lets Low-Pri Admins Execute Arbitrary JavaScript

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-44282 is a medium severity vulnerability affecting decidim-elections versions < 0.32.0 with a CVSS score of 4.8, classified as stored cross-site scripting (XSS). This flaw type allows an attacker to inject malicious JavaScript code that executes in visitor's browsers on public election pages and voting booth screens. The attack vector involves a low-privilege process-scoped admin or other election editor with question-management rights persisting arbitrary HTML in the question statement/body without sanitization, which is then rendered as trusted HTML instead of sanitized text by the public elections UI. This business impact can result in potential unauthorized access and data exposure through cross-site scripting.

RECOMMENDATION:

We recommend you to update decidim-elections to version 0.32.0.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-44282 is a medium severity vulnerability affecting decidim-elections versions < 0.32.0 with a CVSS score of 4.8, classified as stored cross-site scripting (XSS). This flaw type allows an attacker to inject malicious JavaScript code that executes in visitor's browsers on public election pages and voting booth screens. The attack vector involves a low-privilege process-scoped admin or other election editor with question-management rights persisting arbitrary HTML in the question statement/body without sanitization, which is then rendered as trusted HTML instead of sanitized text by the public elections UI. This business impact can result in potential unauthorized access and data exposure through cross-site scripting.

RECOMMENDATION:

We recommend you to update decidim-elections to version 0.32.0.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu