www.vulncheck.com CVE-2026-92602: TDuckCloud Survey Form Vulnerability Exposes User Data
Article Content
- •CVE-2026-92602 allows SSRF via unvalidated webhook URLs in TDuck survey forms.
- •Authenticated attackers can exfiltrate sensitive data from user forms.
- •No confirmed exploitation or public PoC reported as of now.
A vulnerability identified as CVE-2026-92602 affects the TDuck survey form through version 5.3, allowing authenticated attackers to exploit unvalidated webhook URLs. This Server-Side Request Forgery (SSRF) vulnerability can lead to unauthorized access to sensitive survey submissions and potential data exfiltration. The issue poses a high risk for internet-facing instances used for public questionnaires, customer feedback, and similar applications. Although the vulnerability is critical, there is currently no evidence of active exploitation, proof-of-concept code, or a public exploit. Security measures should focus on reviewing webhook configurations and applying vendor patches as soon as they are available. The vulnerability was published on September 16, 2026, and requires urgent attention from affected organizations.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2026-92602 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
SSRF Vulnerability in Sentry MCP Server Exposes Security Risks On July 12, 2026, researcher cccccccti disclosed a Server-Side Request Forgery (SSRF) vulnerability in the raw_sentry_api component of ddfourtwo/sentry-selfhosted-mcp, tracked as CVE-2026-81421. This vulnerability allows attackers to force Axios to call arbitrary endpoints, with a public exploit already available. As…
RamziRange10 Exploit Enhances Vulnerability Testing Tools The RamziRange10 exploit is a deliberately vulnerable web application designed to showcase every weakness class targeted by modern web application scanners. It includes vulnerabilities such as remote code execution, SQL injection, and exposed credentials, all intentionally implemented for educational and testing…