Fides is an open-source privacy engineering platform. From 2.75.0 to before 2.83.2, Fides deployments that enable both subject identity verification and duplicate privacy request detection are affected by a vulnerability in which an administrator can approve a privacy request whose identity was never verified. For erasure policies, this can result in unauthorized deletion of a data subject's records across every integration configured in the affected deployment. This vulnerability is fixed in 2.83.2.
CVSS
No CVSS.
References
Configurations
No configuration.
History
12 May 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/ethyca/fides/security/advisories/GHSA-qx5f-ghc2-7g5c - |
12 May 2026, 18:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-12 18:17
Updated : 2026-05-13 18:24
NVD link : CVE-2026-42303
Mitre link : CVE-2026-42303
CVE.ORG link : CVE-2026-42303
JSON object : View
Products Affected
No product.
