CVE-2025-8756: Tduckcloud Tduck-Platform

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability has been found in TDuckCloud tduck-platform up to 5.1 and classified as critical. Affected by this vulnerability is the function preHandle of the file /manage/ of the component com.tduck.cloud.api.web.interceptor.AuthorizationInterceptor. The manipulation leads to improper authorization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

Affected products

  • Tduckcloud Tduck-Platform: up to and including 5.1

Published 2025-08-09. Last modified 2026-06-17.