CVE-2026-97685
Deferred Deferred - Pending Action

Authenticated Survey Context Bypass in LimeSurvey Community Edition

Vulnerability report for CVE-2026-97685, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: Fluid Attacks

Description

An authenticated LimeSurvey Community Edition 7.3.0 user allowed to create surveys can use their own survey as an authorized context while supplying question or answer identifiers belonging to another user's survey. The REST survey-patching endpoint checks the attacker's permission against the survey ID in the request URL, but the vulnerable persistence operations resolve the target object independently by its global qid or aid and never verify that it belongs to that authorized survey.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
lime_survey lime_survey to 7.4.0 (exc)
lime_survey lime_survey From 6.4.0 (inc) to 7.3.0 (inc)
lime_survey lime_survey 7.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in LimeSurvey Community Edition 7.3.0 allows an authenticated user with survey creation permissions to modify or delete content in other users' surveys. The issue occurs because the system checks permissions against the survey ID in the URL but fails to verify if the target question or answer identifiers belong to that survey. This bypasses ownership isolation.

Detection Guidance

To detect this vulnerability, inspect LimeSurvey instances running version 7.3.0 or earlier for unauthorized modifications to surveys not owned by the authenticated user. Check REST API logs for survey-patching requests where question or answer IDs do not belong to the survey ID in the URL. Verify if users can edit questions or answers in surveys they do not own.

Impact Analysis

An attacker could change question text or delete answer options in your surveys, even active ones. This could mislead respondents, corrupt survey data, disrupt workflows, or cause loss of critical information. The impact depends on the sensitivity of the survey content.

Compliance Impact

This vulnerability could compromise data integrity and confidentiality, which are key requirements under GDPR and HIPAA. Unauthorized modifications to survey data may lead to non-compliance, potential fines, or legal consequences depending on the data processed.

Mitigation Strategies

Upgrade LimeSurvey to version 7.4.0 or later to patch the vulnerability. Review survey permissions and ownership settings to ensure proper isolation between users. Monitor for unauthorized survey modifications or deletions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-97685. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart