CVE-2026-92567 PUBLISHED

TDuck survey form through 5.0 Unauthorized Data Modification

Assigner: VulnCheck
Reserved: 16.09.2026 Published: 16.09.2026 Updated: 16.09.2026

TDuck survey form through version 5.0 contains an authorization bypass vulnerability in the POST /user/form/data/update endpoint that allows authenticated users to overwrite other users' form submission data. Attackers can discover submission identifiers allocated in narrow ranges and modify arbitrary form responses containing personal data by sending update requests without ownership validation.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 7.1

Product Status

Vendor TDuckCloud
Product tduck-survey-form
Versions Default: unaffected
  • affected from 0 to 5.0 (incl.)

Credits

  • George Chen reporter

References

Problem Types

  • Authorization Bypass Through User-Controlled Key CWE