Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 29 Sep 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated LimeSurvey Community Edition 7.3.0 user allowed to create surveys can use their own survey as an authorized context while supplying question or answer identifiers belonging to another user's survey. The REST survey-patching endpoint checks the attacker's permission against the survey ID in the request URL, but the vulnerable persistence operations resolve the target object independently by its global qid or aid and never verify that it belongs to that authorized survey. | |
| Title | LimeSurvey Community Edition 7.3.0 - Cross-survey object authorization bypass in REST survey patch operations | |
| First Time appeared |
Limesurvey
Limesurvey limesurvey |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:limesurvey:limesurvey:7.3.0:*:linux:*:*:*:*:* cpe:2.3:a:limesurvey:limesurvey:7.3.0:*:macos:*:*:*:*:* cpe:2.3:a:limesurvey:limesurvey:7.3.0:*:windows:*:*:*:*:* |
|
| Vendors & Products |
Limesurvey
Limesurvey limesurvey |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2026-09-29T02:20:43.077Z
Reserved: 2026-09-24T21:11:19.206Z
Link: CVE-2026-97685
No data.
Status : Deferred
Published: 2026-09-29T03:17:23.233
Modified: 2026-09-29T03:17:23.360
Link: CVE-2026-97685
No data.
OpenCVE Enrichment
Updated: 2026-09-29T03:30:10Z