CVE-2026-100303

Summary

TDuck survey form through 6.0 lacks authorization checks on FormThemeController write endpoints for global form themes and categories. Authenticated non-admin users can add, modify, or delete themes and theme categories affecting forms owned by other users.

Affected Software

VendorProductVersion RangeStatus
TDuckCloudtduck-survey-form0 <= 6.0affected

Weaknesses

  • CWE-862: Missing Authorization

References