CVE-2026-92567
Last modified
CVE-2026-92567 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. TDuck survey form through version 5.0 contains an authorization bypass vulnerability in the POST /user/form/data/update endpoint that allows authenticated users to overwrite other users' form submission data. Attackers can discover submission identifiers allocated in narrow ranges and modify arbitrary form responses containing personal data by sending update requests without ownership validation..
Description
TDuck survey form through version 5.0 contains an authorization bypass vulnerability in the POST /user/form/data/update endpoint that allows authenticated users to overwrite other users' form submission data. Attackers can discover submission identifiers allocated in narrow ranges and modify arbitrary form responses containing personal data by sending update requests without ownership validation.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| TDuckCloud | tduck-survey-form | <= 5.0 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-92567?
How severe is CVE-2026-92567?
How do I fix CVE-2026-92567?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-9253The WP Cost Estimation & Payment Forms Builder (E&P Forms) p…7.2
- CVE-2026-9254An unauthenticated OS command injection vulnerability exists…8.7
- CVE-2026-9255Missing input source validation in the tool authorization pr…8.4
- CVE-2026-9256NGINX Plus and NGINX Open Source have a vulnerability in the…8.1
- CVE-2026-92565Rallly before 4.15.0 contains an information disclosure vuln…5.3
- CVE-2026-92566DataGear through 6.0.0 contains a server-side request forger…8.2
- CVE-2026-92568MLRun through 1.11.0 contains a server-side request forgery …5.4
- CVE-2026-92569Hippo4j through 1.5.0 contains a server-side request forgery…4.3
- CVE-2026-92570reNgine through 2.2.0 contains an authorization bypass vulne…6.5
- CVE-2026-92571Rejected reason: CVE ID reserved in error and not assigned t…
- CVE-2026-92576HKUDS nanobot before 0.3.0 contains a server-side request fo…8.6
- CVE-2026-92577In AVideo through 29.0, the API get_api_video endpoint conta…7.5
Are you affected by CVE-2026-92567?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
