CVE-2026-100306
MEDIUM
6,9
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM
5,3
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: low
Availability: none
Description
AI Translation Available
TDuck survey form through 6.0 fails to validate write passwords on submission endpoints, enforcing the check only on the front end. Remote unauthenticated attackers can submit form entries directly to public submission APIs without providing the password by using the form key from share links.
602
Client-Side Enforcement of Server-Side Security
DraftCommon Consequences
Security Scopes Affected:
Access Control
Availability
Potential Impacts:
Bypass Protection Mechanism
Dos: Crash, Exit, Or Restart
Gain Privileges Or Assume Identity
Applicable Platforms
Technologies:
ICS/OT, Mobile
https://github.com/LinYuanyi1/cve-request-poc/blob/adffc39b78cad18cd489cbf74548…
https://github.com/TDuckCloud/tduck-survey-form
https://github.com/TDuckCloud/tduck-survey-form/blob/43ffa9c993e38936fc4de7d8e5…
https://github.com/TDuckCloud/tduck-survey-form/blob/43ffa9c993e38936fc4de7d8e5…
https://www.vulncheck.com/advisories/tduck-survey-form-through-6.0-write-passwo…