Skip to content
CVE Alert: CVE-2026-92602 – TDuckCloud – tduck-survey

CVE Alert: CVE-2026-92602 – TDuckCloud – tduck-survey

Redpacketsecurity admin September 17, 2026

TDuck survey form through version 5.3 fails to validate webhook URLs or verify form ownership in the WebhookConfigController. Authenticated attackers can attach webhooks to other users’ forms and exfiltrate submissions to arbitrary external or internal addresses.

This is a high-priority issue for exposed deployments, but the available data does not confirm active exploitation, KEV listing, a public PoC, or an EPSS probability.

A low-privilege account may be sufficient to redirect server-originated requests and expose submitted survey information, creating confidentiality and regulatory risk. Attackers could also use the application as a foothold for probing reachable administration interfaces, cloud metadata services, or internal APIs, although direct impact on those systems is not established.

### Most likely attack path

The practical path is network-based (AV:N), with low complexity and no victim interaction (AC:L, UI:N), requiring only limited authenticated access (PR:L). The unchanged Scope indicates the direct vulnerability remains within the application’s security authority, but SSRF requests may still reach trusted internal resources accessible from the server.

### Who is most exposed

Internet-facing instances used for public questionnaires, customer feedback, recruitment, or event registration are the main concern. Risk increases where the application runs inside a broad-trust cloud or corporate network and stores sensitive responses.

Review webhook configuration changes, especially by ordinary user accounts or against forms they do not own.

Alert on outbound requests from the application process to private, loopback, link-local, and cloud-metadata addresses.

Inspect proxy, DNS, and firewall logs for unusual destinations or high-volume webhook callbacks.

Correlate webhook creation with subsequent access to sensitive survey records.

### Mitigation and prioritisation

Apply the vendor’s security fix as soon as a confirmed fixed release is available; otherwise treat remediation as urgent engineering work.

Enforce strict form-ownership checks and allow-list approved schemes, hosts, ports, and redirect behaviour.

Block server egress to internal ranges and metadata endpoints, preferably at network level.

Test webhook changes in staging, then deploy under change control with rollback prepared.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.