CVE-2023-29492: Novi Survey Insecure Deserialization Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2023-04-13. EPSS: 2.7% chance of exploitation in the next 30 days.

Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not provide access to stored survey or response data.

Affected products

  • 3rdmill Novi Survey: before 8.9.43676 (fixed in 8.9.43676)

Published 2023-04-11. Last modified 2026-06-17.