Medium severity5.3NVD Advisory· Published Sep 25, 2026
CVE-2026-100306
CVE-2026-100306
Description
TDuck survey form through 6.0 fails to validate write passwords on submission endpoints, enforcing the check only on the front end. Remote unauthenticated attackers can submit form entries directly to public submission APIs without providing the password by using the form key from share links.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=6.0
Patches
Vulnerability mechanics
References
4- github.com/LinYuanyi1/cve-request-poc/blob/adffc39b78cad18cd489cbf7454853bf0f744b7f/tduck/poc_form_data_create_bypass.pynvd
- github.com/TDuckCloud/tduck-survey-form/blob/43ffa9c993e38936fc4de7d8e5aee82bbaa19502/tduck-api/src/main/java/com/tduck/cloud/api/web/controller/UserFormResultController.javanvd
- github.com/TDuckCloud/tduck-survey-form/blob/43ffa9c993e38936fc4de7d8e5aee82bbaa19502/tduck-api/src/main/java/com/tduck/cloud/api/web/controller/UserFormSettingController.javanvd
- www.vulncheck.com/advisories/tduck-survey-form-through-6.0-write-password-bypass-via-client-side-enforcementnvd
News mentions
0No linked articles in our index yet.