Improper Authorization Vulnerability in LimeSurvey Community Edition
CVE-2026-65931

5.1MEDIUM

Key Information:

Vendor

Limesurvey

Vendor
CVE Published:
27 August 2026

What is CVE-2026-65931?

LimeSurvey Community Edition version 7.0.5 has a vulnerability that allows authenticated users with minimal permission to exploit the survey menu entry creation endpoint. Specifically, users with the 'global settings:read' permission can execute POST requests to create new survey menu entries without having the necessary 'settings:update' privilege. This flaw allows these users to manipulate menu IDs, circumventing intended restrictions, and to make unauthorized changes to admin navigation records. It poses significant security risks as it could lead to unauthorized access to sensitive administrative functions.

Affected Version(s)

LimeSurvey Windows 7.0.5

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Miguel GĂłmez
.