CVE-2026-92567: TDuck survey form through 5.0 Unauthorized Data Modification

Published Sep 16, 2026
·
Updated

TDuck survey form through version 5.0 contains an authorization bypass vulnerability in the POST /user/form/data/update endpoint that allows authenticated users to overwrite other users' form submission data. Attackers can discover submission identifiers allocated in narrow ranges and modify arbitrary form responses containing personal data by sending update requests without ownership validation.

Affected Software

1 affected component
TDuck survey form<=5.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade TDuck survey form to a version that resolves this vulnerability.

    Fixed in 5.0

Event History

Sep 16, 2026
CVE Published
via MITRE·02:40 PM
Data Sourced
via MITRE·02:40 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any authenticated TDuck survey form user can exploit it. The attacker does not need to own the targeted submission because the update endpoint does not validate ownership.

2

What does an attacker need to modify another user's submission?

The attacker needs a valid account and a target submission identifier. Submission identifiers may be discoverable because they are allocated in narrow ranges.

3

Are systems exposed by default?

The affected POST /user/form/data/update endpoint is vulnerable through TDuck survey form version 5.0 when authenticated users can reach it. The provided information does not identify a configuration prerequisite or mitigation setting.

4

How can I determine whether this has been exploited?

Review requests to POST /user/form/data/update for updates where the authenticated user differs from the owner of the modified form submission. Also investigate modifications involving unexpected or sequentially adjacent submission identifiers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203