CVE-2026-97685: LimeSurvey Community Edition 7.3.0 - Cross-survey object authorization bypass in REST survey patch operations

Published Sep 29, 2026
·
Updated

An authenticated LimeSurvey Community Edition 7.3.0 user allowed to create surveys can use their own survey as an authorized context while supplying question or answer identifiers belonging to another user's survey. The REST survey-patching endpoint checks the attacker's permission against the survey ID in the request URL, but the vulnerable persistence operations resolve the target object independently by its global qid or aid and never verify that it belongs to that authorized survey.

Affected Software

1 affected component
Limesurvey Community Edition=7.3.0

Event History

Sep 29, 2026
CVE Published
via MITRE·02:20 AM
Data Sourced
via MITRE·02:20 AM
DescriptionWeakness
Data Sourced
via NVD·03:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated LimeSurvey Community Edition 7.3.0 user who is permitted to create surveys can exploit it. The user does not need permission on the survey that owns the targeted question or answer.

2

What does an attacker need to supply in a malicious request?

The attacker needs an authorized survey ID in the REST survey-patching request URL, typically for a survey they control, plus a global question ID (qid) or answer ID (aid) belonging to another user's survey. The affected endpoint validates access to the URL survey but does not verify that the referenced object belongs to it.

3

How can I determine whether a survey may have been affected?

Review REST survey-patching activity performed by users with survey-creation permission for requests where the survey ID in the URL differs from the survey that owns the referenced qid or aid. Changes to questions or answers in a user's survey made by an account without permission to that survey are indicative of exploitation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203