Information Disclosure Vulnerability in TDuck Survey Form by TDuckCloud
CVE-2026-100304
Key Information:
- Vendor
Tduckcloud
- Status
- Vendor
- CVE Published:
- 25 September 2026
Badges
What is CVE-2026-100304?
The TDuck Survey Form 6.0 has a significant information disclosure issue wherein the FormAuthUtils.hasPermission method operates in a fail-open mode. This flaw allows authenticated users to access submissions from forms that are no longer valid. Specifically, when a user provides a dataId for a previously deleted form, they can retrieve orphaned submission data, which may include sensitive personal information. This vulnerability occurs due to improper checks in the system that fail to prevent unauthorized access after form deletion.
Affected Version(s)
tduck-survey-form 6.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
