LimeSurvey constructs account password-reset links from the client-supplied HTTP Host header without validating it. (CVE-2026-50635)
LimeSurvey constructs account password-reset links from the client-supplied HTTP Host header without validating it. The optional allowedHosts allowlist that would constrain this is undefined in the default (and documented) configuration, so LSHttpRequest::checkIsAllowedHost() results in no operation. A remote, unauthenticated attacker who submits a forgotten-password request for a known account (requiring only the target's username and email) with a spoofed Host header causes LimeSurvey to email that account a reset link whose hostname is attacker-controlled while embedding the genuine validation_key. When the recipient or an automated inbound mail-security link scanner dereferences the link, the valid reset token is disclosed to the attacker, who replays it against the legitimate host's newPassword endpoint to set a new password and take over the account.
AI Analysis
Technical Summary
LimeSurvey's password reset functionality relies on the HTTP Host header to build reset links. The optional allowedHosts allowlist intended to restrict acceptable Host headers is undefined by default, resulting in no validation. An attacker can exploit this by sending a password reset request for a known user with a spoofed Host header, causing the reset email to include a link with an attacker-controlled hostname embedding the genuine reset token. Accessing this link discloses the token to the attacker, who can then use it to reset the victim's password and gain account control. This vulnerability is tracked as CVE-2026-50635 and has a CVSS 3.1 score of 8.8 (high severity).
Potential Impact
An unauthenticated remote attacker can cause LimeSurvey to send password reset emails containing attacker-controlled links with valid reset tokens. This leads to disclosure of the reset token to the attacker when the link is accessed, enabling the attacker to reset the victim's password and take over the account. The vulnerability affects confidentiality, integrity, and availability of user accounts.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, administrators should consider configuring the allowedHosts parameter to explicitly restrict acceptable Host headers if supported. Monitoring for suspicious password reset requests and educating users about phishing risks may help reduce impact. Do not rely on default configurations that leave allowedHosts undefined.
LimeSurvey constructs account password-reset links from the client-supplied HTTP Host header without validating it. (CVE-2026-50635)
Description
LimeSurvey constructs account password-reset links from the client-supplied HTTP Host header without validating it. The optional allowedHosts allowlist that would constrain this is undefined in the default (and documented) configuration, so LSHttpRequest::checkIsAllowedHost() results in no operation. A remote, unauthenticated attacker who submits a forgotten-password request for a known account (requiring only the target's username and email) with a spoofed Host header causes LimeSurvey to email that account a reset link whose hostname is attacker-controlled while embedding the genuine validation_key. When the recipient or an automated inbound mail-security link scanner dereferences the link, the valid reset token is disclosed to the attacker, who replays it against the legitimate host's newPassword endpoint to set a new password and take over the account.
CVSS v3.1
Score 8.8high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
LimeSurvey's password reset functionality relies on the HTTP Host header to build reset links. The optional allowedHosts allowlist intended to restrict acceptable Host headers is undefined by default, resulting in no validation. An attacker can exploit this by sending a password reset request for a known user with a spoofed Host header, causing the reset email to include a link with an attacker-controlled hostname embedding the genuine reset token. Accessing this link discloses the token to the attacker, who can then use it to reset the victim's password and gain account control. This vulnerability is tracked as CVE-2026-50635 and has a CVSS 3.1 score of 8.8 (high severity).
Potential Impact
An unauthenticated remote attacker can cause LimeSurvey to send password reset emails containing attacker-controlled links with valid reset tokens. This leads to disclosure of the reset token to the attacker when the link is accessed, enabling the attacker to reset the victim's password and take over the account. The vulnerability affects confidentiality, integrity, and availability of user accounts.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, administrators should consider configuring the allowedHosts parameter to explicitly restrict acceptable Host headers if supported. Monitoring for suspicious password reset requests and educating users about phishing risks may help reduce impact. Do not rely on default configurations that leave allowedHosts undefined.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-5c37-5j7w-8mh8
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-50635"]
- Ecosystems
- ["Packagist"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a6d13aebf32cb7a3457feb4
Added to database: 07/31/2026, 21:29:18 UTC
Last enriched: 07/31/2026, 21:33:15 UTC
Last updated: 09/14/2026, 22:01:35 UTC
Views: 82
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.