CVE-2026-65931

LOWCVSS 5.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

LimeSurvey Community Edition 7.0.5 contains an authenticated improper authorization vulnerability in the survey menu entry creation endpoint. An authenticated user with only the global settings:read permission can directly invoke POST /index.php/admin/menuentries/sa/create and create new survey menu entries without the expected settings:update privilege. The endpoint also allows the attacker to submit menu IDs that the normal interface and intended update workflow restrict for non-superadministrators, enabling unauthorized changes to administrative navigation records. This issue affects LimeSurvey: 7.0.5.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-29: 109-29
Referenced assets2 URLs
By indicator
Full discourse1 post
  • Fluid Attacks@fluidattacks

    Fluid Attacks' research team found a zero-day vulnerability in LimeSurvey. As a #CNA, we assigned the ID CVE-2026-65931. Details here: 🔗 https://fluidattacks.com/advisories/coda. We have disclosed 277 #CVE to this date: 🔗https://fluidattacks.com/advisories/. https://t.co/lXY9jRFfcs

    0101072
    900 followersView on X

Explore more