CVE-2026-97685 Details
Description
An authenticated LimeSurvey Community Edition 7.3.0 user allowed to create surveys can use their own survey as an authorized context while supplying question or answer identifiers belonging to another user's survey. The REST survey-patching endpoint checks the attacker's permission against the survey ID in the request URL, but the vulnerable persistence operations resolve the target object independently by its global qid or aid and never verify that it belongs to that authorized survey.
A broken access control vulnerability has been identified in LimeSurvey Community Edition version 7.3.0. This issue allows authenticated users with survey creation permissions to manipulate questions and answers in surveys owned by other users. The vulnerability arises because the REST API's survey-patching endpoint only checks permissions against the survey ID in the request URL, while the actual operations are based on global question or answer identifiers, bypassing the intended access controls.
Users are advised to update to LimeSurvey version 7.4.0 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://fluidattacks.com/es/advisories/zoo | CISA-ADP | AdvisoryBundleContent Wall |
| https://fluidattacks.com/es/advisories/zoo | [email protected] | AdvisoryBundleContent Wall |
| https://github.com/LimeSurvey/LimeSurvey/ | [email protected] | ProductVendor |
| https://github.com/LimeSurvey/LimeSurvey/commit/a39a01537a8f79581bd630bcac94f71ae6ce2cce | [email protected] | Source CodeVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| LimeSurvey | >= 6.4.0, <= 7.3.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion