CVE-2026-100304

MEDIUM Status: Received

CVSS Scores

CVSS v3.x Base Score
5.3
MEDIUM

Description

TDuck survey form 6.0 contains an information disclosure vulnerability in FormAuthUtils.hasPermission that fails open when a form does not exist, allowing authenticated users to access deleted form submissions. Attackers can read orphaned submission data including personal information by providing a known dataId to the GET /user/form/data/details endpoint after the form has been permanently deleted.

Published
September 25, 2026 7:16 PM
Last Modified
September 25, 2026 7:16 PM
Source
[email protected]

Weaknesses (CWE)

CWE-636

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.