Improper Authorization Vulnerability in LimeSurvey Community Edition
CVE-2026-65931
5.1MEDIUM
What is CVE-2026-65931?
LimeSurvey Community Edition version 7.0.5 has a vulnerability that allows authenticated users with minimal permission to exploit the survey menu entry creation endpoint. Specifically, users with the 'global settings:read' permission can execute POST requests to create new survey menu entries without having the necessary 'settings:update' privilege. This flaw allows these users to manipulate menu IDs, circumventing intended restrictions, and to make unauthorized changes to admin navigation records. It poses significant security risks as it could lead to unauthorized access to sensitive administrative functions.
Affected Version(s)
LimeSurvey Windows 7.0.5
