CVE-2026-97685
Deferred
Deferred - Pending Action
Authenticated Survey Context Bypass in LimeSurvey Community Edition
Vulnerability report for CVE-2026-97685, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-29
Last updated on: 2026-09-29
Assigner: Fluid Attacks
Description
Description
An authenticated LimeSurvey Community Edition 7.3.0 user allowed to create surveys can use their own survey as an authorized context while supplying question or answer identifiers belonging to another user's survey. The REST survey-patching endpoint checks the attacker's permission against the survey ID in the request URL, but the vulnerable persistence operations resolve the target object independently by its global qid or aid and never verify that it belongs to that authorized survey.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| lime_survey | lime_survey | to 7.4.0 (exc) |
| lime_survey | lime_survey | From 6.4.0 (inc) to 7.3.0 (inc) |
| lime_survey | lime_survey | 7.4.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-639 | The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data. |