CVE-2026-100304: Tduckcloud Tduck-Survey-Form
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
TDuck survey form 6.0 contains an information disclosure vulnerability in FormAuthUtils.hasPermission that fails open when a form does not exist, allowing authenticated users to access deleted form submissions. Attackers can read orphaned submission data including personal information by providing a known dataId to the GET /user/form/data/details endpoint after the form has been permanently deleted.
Affected products
- Tduckcloud Tduck-Survey-Form: version 6.0 only
Published 2026-09-25. Last modified 2026-09-29.