CVE-2026-14792: Formbricks Survey actions.ts access control
A security vulnerability has been detected in Formbricks 5.0.0. This impacts an unknown function of the file apps/web/modules/survey/link/actions.ts of the component Survey Handler. The manipulation leads to improper access controls. Remote exploitation of the attack is possible. Upgrading to version 5.1.0-rc.1 will fix this issue. The identifier of the patch is af6023b5ac3b030ffcea24fac799f76f3e3512c6. You should upgrade the affected component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Formbricksto a version that resolves this vulnerability.Fixed in 5.1.0-rc.1Patch af6023b5ac3b030ffcea24fac799f76f3e3512c6
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14792?
The severity of CVE-2026-14792 is categorized as medium with a score of 6.5.
How do I fix CVE-2026-14792?
To fix CVE-2026-14792, update Formbricks to a version that addresses the access control vulnerabilities.
What component is affected by CVE-2026-14792?
CVE-2026-14792 affects the Survey Handler component in the Formbricks application.
Can CVE-2026-14792 be exploited remotely?
Yes, CVE-2026-14792 can be exploited remotely due to improper access controls.
What is the impact of CVE-2026-14792?
The impact of CVE-2026-14792 is improper access controls that could lead to unauthorized actions in the Formbricks application.