CVE-2026-100304 | TDuck survey form 6.0 contains an information disclosure vulnerability in FormAuthUtils.hasPermission that fails open when a form does not exist, allowing authenticated users to access deleted form submissions. Attackers can read orphaned submission data including personal information by providing a known dataId to the GET /user/form/data/details endpoint after the form has been permanently deleted.
TDuck survey form 6.0 contains an information disclosure vulnerability in FormAuthUtils.hasPermission that fails open when a form does not exist, allowing authenticated users to access deleted form submissions. Attackers can read orphaned submission data including personal information by providing a known dataId to the GET /user/form/data/details endpoint after the form has been permanently deleted.
- 🔗 github.com/LinYuanyi1/cve-request-poc/blob/adffc39b7…
- 🔗 github.com/TDuckCloud/tduck-survey-form
- 🔗 github.com/TDuckCloud/tduck-survey-form/blob/43ffa9c…
- 🔗 github.com/TDuckCloud/tduck-survey-form/blob/43ffa9c…
- 🔗 github.com/TDuckCloud/tduck-survey-form/blob/43ffa9c…
- 🔗 www.vulncheck.com/advisories/tduck-survey-form-6.0-informat…
```Code``` unterstützt. Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-09-13 | 2026-09-26 |
|---|---|---|
| ≥90 % | 0 | 497 |
| ≥50 % | 0 | 1467 |
| ≥10 % | 0 | 1 |
| <10 % | 300 | 0 |
CVE-2026-100304 | TDuck survey form 6.0 contains an information disclosure vulnerability in FormAuthUtils.hasPermission that fails open when a form does not exist, allowing authenticated users to access deleted form submissions. Attackers can read orphaned submission data including personal information by providing a known dataId to the GET /user/form/data/details endpoint after the form has been permanently deleted.
TDuck survey form 6.0 contains an information disclosure vulnerability in FormAuthUtils.hasPermission that fails open when a form does not exist, allowing authenticated users to access deleted form submissions. Attackers can read orphaned s
Noch keine Analyse zu CVE-2026-100304
Sei der Erste: Einschätzung, Betroffenheit, Workaround oder PoC — mit Antworten im Thread.