All findings

CVE-2026-13229, CVE-2026-18403, CVE-2026-63361 high

Fluid Attacks' AI SAST adds three August CVEs

Fluid Attacks' public advisories directly credit its AI SAST Scanner on Zammad and LimeSurvey authorization, SQL-injection, and XSS vulnerabilities.

Bug class
Improper authorization, authenticated SQL injection, and reflected XSS
Affected codebase
Zammad and LimeSurvey Community Edition
Credited system
Fluid Attacks AI SAST
Disclosed
August 14, 2026
Attribution
Direct source attribution
Severity
high
Source status: The CNA records and Fluid advisory pages explicitly credit Fluid Attacks' AI SAST Scanner. Human analysts validated the reports before assignment and coordinated disclosure; upstream scores range from medium to high.

Summary

CVE-2026-13229 concerns ticket-article attachment cloning in Zammad. CVE-2026-18403 is an authenticated SQL injection in LimeSurvey’s central participant database, and CVE-2026-63361 is reflected XSS in a LimeSurvey HTML editor popup.

Fluid’s public workflow makes the human role explicit: the scanner generates candidates, while analysts verify reachability, reproduce impact, deduplicate, and coordinate disclosure.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.