CVE-2026-100303 UNKNOWN

CVE-2026-100303

Published: 2026-09-25

Description

TDuck survey form through 6.0 lacks authorization checks on FormThemeController write endpoints for global form themes and categories. Authenticated non-admin users can add, modify, or delete themes and theme categories affecting forms owned by other users.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…