Unknown · Lime Survey Community Edition · CVE-2026-65931
**Name of the Vulnerable Software and Affected Versions**
LimeSurvey Community Edition version 7.0.5
**Description**
An authenticated user possessing only the `settings:read` global permission can bypass authorization requirements to create new survey menu entries. This is achieved by directly invoking the POST '/index.php/admin/menuentries/sa/create' endpoint without the necessary `settings:update` privilege. Additionally, the endpoint allows the submission of menu IDs that are typically restricted to superadministrators, enabling unauthorized modifications to administrative navigation records.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.