CVE-2026-65931

Source
https://cve.org/CVERecord?id=CVE-2026-65931
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-65931.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-65931
Published
2026-08-27T17:50:47.311Z
Modified
2026-08-30T03:30:45.721581775Z
Severity
  • 5.1 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
LimeSurvey Community Edition 7.0.5 - Improper authorization in survey menu entry creation endpoint
Details

LimeSurvey Community Edition 7.0.5 contains an authenticated improper authorization vulnerability in the survey menu entry creation endpoint.

An authenticated user with only the global settings:read permission can directly invoke POST /index.php/admin/menuentries/sa/create and create new survey menu entries without the expected settings:update privilege. The endpoint also allows the attacker to submit menu IDs that the normal interface and intended update workflow restrict for non-superadministrators, enabling unauthorized changes to administrative navigation records.

This issue affects LimeSurvey: 7.0.5.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/65xxx/CVE-2026-65931.json",
    "cwe_ids": [
        "CWE-862"
    ],
    "cna_assigner": "Fluid Attacks"
}
References

Affected packages

Git / github.com/limesurvey/limesurvey

Affected ranges

Type
GIT
Repo
https://github.com/limesurvey/limesurvey
Events
Database specific
Show details
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "7.0.5"
        },
        {
            "last_affected": "7.0.5"
        }
    ]
}

Affected versions

7.*
7.0.5
7.0.5+260623

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-65931.json"