Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-65931— LimeSurvey Community Edition 7.0.5 - Improper authorization in survey menu entry creation endpoint

Quick assessment

Affected
LimeSurvey LimeSurvey
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

LimeSurvey 社区版 7.0.5 在“调查菜单项创建”接口中存在一个经过身份验证的不当授权(improper authorization)漏洞。 具体而言,仅拥有“全局设置:读取(global settings:read)”权限的已认证用户,可以直接调用 接口创建新的调查菜单项,而无需具备本应要求的“设置:更新(settings:update)”权限。此外,该接口还允许攻击者提交那些在正常界面和预期更新流程中已被限制为非超级管理员可用的菜单 ID,从而实现对管理导航记录的未授权修改。 此问题影响范围:Lim

CVSS 5.1 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-65931

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
LimeSurvey Community Edition 7.0.5 - Improper authorization in survey menu entry creation endpoint
Source: CVE Program / CVE List V5
Vulnerability Description
LimeSurvey Community Edition 7.0.5 contains an authenticated improper authorization vulnerability in the survey menu entry creation endpoint. An authenticated user with only the global settings:read permission can directly invoke POST /index.php/admin/menuentries/sa/create and create new survey menu entries without the expected settings:update privilege. The endpoint also allows the attacker to submit menu IDs that the normal interface and intended update workflow restrict for non-superadministrators, enabling unauthorized changes to administrative navigation records. This issue affects LimeSurvey: 7.0.5.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
LimeSurvey LimeSurvey 7.0.5 -

II. Public POCs for CVE-2026-65931

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-65931

登录查看更多情报信息。

Vendor Advisories for CVE-2026-65931 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-65931

No comments yet


Leave a comment