An authenticated LimeSurvey Community Edition 7.3.0 user allowed to create surveys can use their own survey as an authorized context while supplying… (CVE-2026-97685)
An authenticated LimeSurvey Community Edition 7.3.0 user allowed to create surveys can use their own survey as an authorized context while supplying question or answer identifiers belonging to another user's survey. The REST survey-patching endpoint checks the attacker's permission against the survey ID in the request URL, but the vulnerable persistence operations resolve the target object independently by its global qid or aid and never verify that it belongs to that authorized survey.
AI Analysis
Technical Summary
CVE-2026-97685 describes an authorization bypass vulnerability in LimeSurvey Community Edition 7.3.0. An authenticated user permitted to create surveys can supply question or answer IDs from another user's survey to the REST survey-patching endpoint. While the endpoint checks permissions against the survey ID in the URL, the persistence layer resolves target objects by their global question or answer IDs without verifying that these belong to the authorized survey. This allows unauthorized modification of survey data across user boundaries.
Potential Impact
The vulnerability allows an authenticated user with survey creation rights to modify questions or answers in surveys owned by other users. This could lead to unauthorized data tampering within the LimeSurvey platform, potentially compromising survey integrity and trustworthiness. There is no indication of privilege escalation beyond survey data modification or of impact on system-wide controls.
Mitigation Recommendations
No official patch or remediation information is provided. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict survey creation permissions to trusted users only and monitor for unusual survey modifications.
An authenticated LimeSurvey Community Edition 7.3.0 user allowed to create surveys can use their own survey as an authorized context while supplying… (CVE-2026-97685)
Description
An authenticated LimeSurvey Community Edition 7.3.0 user allowed to create surveys can use their own survey as an authorized context while supplying question or answer identifiers belonging to another user's survey. The REST survey-patching endpoint checks the attacker's permission against the survey ID in the request URL, but the vulnerable persistence operations resolve the target object independently by its global qid or aid and never verify that it belongs to that authorized survey.
CVSS v4.0
Affected software
pkg:github/limesurvey/LimeSurveyRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-97685 describes an authorization bypass vulnerability in LimeSurvey Community Edition 7.3.0. An authenticated user permitted to create surveys can supply question or answer IDs from another user's survey to the REST survey-patching endpoint. While the endpoint checks permissions against the survey ID in the URL, the persistence layer resolves target objects by their global question or answer IDs without verifying that these belong to the authorized survey. This allows unauthorized modification of survey data across user boundaries.
Potential Impact
The vulnerability allows an authenticated user with survey creation rights to modify questions or answers in surveys owned by other users. This could lead to unauthorized data tampering within the LimeSurvey platform, potentially compromising survey integrity and trustworthiness. There is no indication of privilege escalation beyond survey data modification or of impact on system-wide controls.
Mitigation Recommendations
No official patch or remediation information is provided. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict survey creation permissions to trusted users only and monitor for unusual survey modifications.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-c7fj-2fxp-jqpf
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-97685"]
- Database Specific Severity
- HIGH
- Cvss Version
- 4.0
Threat ID: 6abb4176f7a7c54106cc2cb9
Added to database: 09/29/2026, 04:41:26 UTC
Last enriched: 09/29/2026, 04:42:44 UTC
Last updated: 09/29/2026, 18:11:22 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.