PT-2026-93812 · Tduckcloud+1 · Tduck-Survey-Form

·

CVE-2026-92567

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions TDuck survey form versions prior to 5.1
Description An authorization bypass exists in the 'POST /user/form/data/update' endpoint. This issue allows authenticated users to overwrite form submission data belonging to other users. Attackers can identify submission identifiers allocated in narrow ranges and modify arbitrary form responses containing personal data because the system fails to validate ownership when processing update requests.
Recommendations Update TDuck survey form to version 5.1 or later. As a temporary mitigation, restrict access to the 'POST /user/form/data/update' endpoint.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92567

Affected Products

Tduck-Survey-Form