CVE-2026-100306: TDuck survey form through 6.0 Write Password Bypass via Client-Side Enforcement

Published Sep 25, 2026
·
Updated

TDuck survey form through 6.0 fails to validate write passwords on submission endpoints, enforcing the check only on the front end. Remote unauthenticated attackers can submit form entries directly to public submission APIs without providing the password by using the form key from share links.

Affected Software

1 affected component
TDuck survey form<=6.0

Event History

Sep 25, 2026
CVE Published
via MITRE·06:47 PM
Data Sourced
via MITRE·06:47 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Any TDuck survey form deployment through 6.0 with a publicly shared form that relies on a write password to restrict submissions is exposed. An attacker only needs the form key available in the form's share link.

2

What does an attacker need to exploit it?

No authentication, password, or user interaction is required. The attacker can send a submission directly to the public submission API using the form key, bypassing the client-side password check.

3

Are forms protected only by a write password affected by default?

Yes. The issue exists because write-password validation is enforced in the front end rather than on the submission endpoint, so the password does not prevent direct API submissions.

4

How can I tell whether a form has been abused?

Review submitted entries for unexpected or unauthorized responses, particularly on forms shared publicly and configured with a write password. The provided data does not identify a specific server-side indicator that distinguishes bypassed submissions from normal ones.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203