Description
TDuck survey form through version 5.0 contains an authorization bypass vulnerability in the POST /user/form/data/update endpoint that allows authenticated users to overwrite other users' form submission data. Attackers can discover submission identifiers allocated in narrow ranges and modify arbitrary form responses containing personal data by sending update requests without ownership validation.
Published: 2026-09-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Modification
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an authorization bypass that allows any authenticated user to overwrite the form submission data of another user via the POST /user/form/data/update endpoint. Because the endpoint does not verify submission ownership, an attacker who can discover the narrow-range identifiers can submit arbitrary updates that replace personal data, potentially changing sensitive information without consent.

Affected Systems

Version 5.0 or earlier of the TDuckCloud "tduck-survey-form" product is affected. No additional patch versions are listed in the CNA data; therefore any installation of 5.0 or earlier should be considered vulnerable.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity risk. The EPSS score of less than 1% suggests a low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. However, because the endpoint is exposed over the web, remote attackers with valid credentials can exploit the flaw once they identify a submission ID, which is readily discoverable due to its narrow range. The lack of ownership validation directly enables the malicious overwrite of user data.

Generated by OpenCVE AI on September 18, 2026 at 05:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the tduck-survey-form installation to a version newer than 5.0 where the ownership check on the update endpoint has been implemented.
  • Ensure that the POST /user/form/data/update endpoint performs strict ownership validation so that only the user who created a submission can modify it.
  • Apply input validation and proper access controls following CWE-639 best practices to prevent unauthorized modifications.
  • Implement rate limiting and monitor the update endpoint for unusual activity to detect potential abuse.

Generated by OpenCVE AI on September 18, 2026 at 05:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Tduckcloud
Tduckcloud tduck-survey-form
Vendors & Products Tduckcloud
Tduckcloud tduck-survey-form
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description TDuck survey form through version 5.0 contains an authorization bypass vulnerability in the POST /user/form/data/update endpoint that allows authenticated users to overwrite other users' form submission data. Attackers can discover submission identifiers allocated in narrow ranges and modify arbitrary form responses containing personal data by sending update requests without ownership validation.
Title TDuck survey form through 5.0 Unauthorized Data Modification
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Tduckcloud Tduck-survey-form
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:22:40.585Z

Reserved: 2026-09-16T13:34:38.760Z

Link: CVE-2026-92567

cve-icon Vulnrichment

Updated: 2026-09-17T19:16:42.999Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T15:19:02.287

Modified: 2026-09-24T21:08:55.030

Link: CVE-2026-92567

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T05:45:03Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key