CVE-2026-100303: TDuck survey form through 6.0 Missing Authorization in Form Theme Management Endpoints
TDuck survey form through 6.0 lacks authorization checks on FormThemeController write endpoints for global form themes and categories. Authenticated non-admin users can add, modify, or delete themes and theme categories affecting forms owned by other users.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated non-admin user can exploit the affected FormThemeController write endpoints. The issue affects global form themes and theme categories, including those used by forms owned by other users.
What access does an attacker need?
The attacker needs a valid authenticated user account; administrator privileges and user interaction are not required. Exploitation can be performed over the network with low attack complexity.
What could an attacker change?
An attacker can add, modify, or delete global form themes and theme categories. These changes can affect forms belonging to other users.
Which versions are affected?
TDuck survey form through version 6.0 is affected.