Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-qx5f-ghc2-7g5c | Ethyca Fides has a Privacy Request Identity Verification Bypass Vulnerability via Duplicate Detection |
Tue, 12 May 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ethyca
Ethyca fides |
|
| Vendors & Products |
Ethyca
Ethyca fides |
Tue, 12 May 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 12 May 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Fides is an open-source privacy engineering platform. From 2.75.0 to before 2.83.2, Fides deployments that enable both subject identity verification and duplicate privacy request detection are affected by a vulnerability in which an administrator can approve a privacy request whose identity was never verified. For erasure policies, this can result in unauthorized deletion of a data subject's records across every integration configured in the affected deployment. This vulnerability is fixed in 2.83.2. | |
| Title | Fides: Privacy Request Identity Verification Bypass Vulnerability via Duplicate Detection | |
| Weaknesses | CWE-288 CWE-306 CWE-841 |
|
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-12T18:40:09.815Z
Reserved: 2026-04-26T12:13:55.552Z
Link: CVE-2026-42303
Updated: 2026-05-12T18:39:06.577Z
Status : Deferred
Published: 2026-05-12T18:17:24.540
Modified: 2026-05-13T18:24:31.310
Link: CVE-2026-42303
No data.
OpenCVE Enrichment
Updated: 2026-05-12T23:30:26Z
Github GHSA