CVE-2026-97685: LimeSurvey Community Edition 7.3.0 - Cross-survey object authorization bypass in REST survey patch operations
An authenticated LimeSurvey Community Edition 7.3.0 user allowed to create surveys can use their own survey as an authorized context while supplying question or answer identifiers belonging to another user's survey. The REST survey-patching endpoint checks the attacker's permission against the survey ID in the request URL, but the vulnerable persistence operations resolve the target object independently by its global qid or aid and never verify that it belongs to that authorized survey.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated LimeSurvey Community Edition 7.3.0 user who is permitted to create surveys can exploit it. The user does not need permission on the survey that owns the targeted question or answer.
What does an attacker need to supply in a malicious request?
The attacker needs an authorized survey ID in the REST survey-patching request URL, typically for a survey they control, plus a global question ID (qid) or answer ID (aid) belonging to another user's survey. The affected endpoint validates access to the URL survey but does not verify that the referenced object belongs to it.
How can I determine whether a survey may have been affected?
Review REST survey-patching activity performed by users with survey-creation permission for requests where the survey ID in the URL differs from the survey that owns the referenced qid or aid. Changes to questions or answers in a user's survey made by an account without permission to that survey are indicative of exploitation.