CVE-2026-75325: DWSurvey vulnerability
Published Aug 26, 2026
·Updated
DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '/api/dwsurvey/up/' parameters.
Affected Software
1 affected component
DWSurvey=6.14.0
Event History
Aug 26, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:17 PM
Description
Frequently Asked Questions
1
Which deployments are confirmed to be affected?
The provided information identifies DWSurvey v6.14.0 as affected. It does not establish whether earlier or later versions are vulnerable.
2
How can I check whether an instance may be exposed?
Confirm whether the instance is running DWSurvey v6.14.0 and assess access controls for the /api/dwsurvey/none/ and /api/dwsurvey/up/** API paths. The provided information does not specify a safe detection method or the actions available through these paths.