CVE-2026-100306
Received Received - Intake

TDuick Survey Form Password Bypass via API

Vulnerability report for CVE-2026-100306, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-25

Last updated on: 2026-09-25

Assigner: VulnCheck

Description

TDuck survey form through 6.0 fails to validate write passwords on submission endpoints, enforcing the check only on the front end. Remote unauthenticated attackers can submit form entries directly to public submission APIs without providing the password by using the form key from share links.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-25
Last Modified
2026-09-25
Generated
2026-09-26
AI Q&A
2026-09-26
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-602 The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

TDuck survey form through version 6.0 does not validate write passwords on submission endpoints, only checking them on the front end. This allows remote unauthenticated attackers to submit form entries directly to public APIs using the form key from share links without providing the required password.

Detection Guidance

To detect this vulnerability, monitor network traffic for direct submissions to TDuck survey form APIs without password validation. Check if form entries are accepted when no password is provided in requests. Inspect server logs for unauthorized form submissions using form keys from share links.

Impact Analysis

Attackers could submit unauthorized form entries, potentially altering or corrupting survey data. This may lead to incorrect results, data integrity issues, or denial of service if the system is overwhelmed with submissions.

Compliance Impact

This vulnerability could impact compliance by allowing unauthorized data submissions, potentially violating integrity and confidentiality requirements in GDPR and HIPAA. Organizations may face risks of non-compliance due to compromised data integrity.

Mitigation Strategies

Update TDuck survey form to a version that validates write passwords on submission endpoints server-side. If no update is available, restrict access to public submission APIs or implement server-side password validation manually.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100306. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart