Skip to content
CVE-2026-92602: TDuckCloud Survey Form Vulnerability Exposes User Data

CVE-2026-92602: TDuckCloud Survey Form Vulnerability Exposes User Data

First seen 17 Sep 2026, 01:23 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 17, 2026 at 03:51 UTC
  • CVE-2026-92602 allows SSRF via unvalidated webhook URLs in TDuck survey forms.
  • Authenticated attackers can exfiltrate sensitive data from user forms.
  • No confirmed exploitation or public PoC reported as of now.

A vulnerability identified as CVE-2026-92602 affects the TDuck survey form through version 5.3, allowing authenticated attackers to exploit unvalidated webhook URLs. This Server-Side Request Forgery (SSRF) vulnerability can lead to unauthorized access to sensitive survey submissions and potential data exfiltration. The issue poses a high risk for internet-facing instances used for public questionnaires, customer feedback, and similar applications. Although the vulnerability is critical, there is currently no evidence of active exploitation, proof-of-concept code, or a public exploit. Security measures should focus on reviewing webhook configurations and applying vendor patches as soon as they are available. The vulnerability was published on September 16, 2026, and requires urgent attention from affected organizations.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-16
CVE-2026-92602 published
The vulnerability affecting TDuck survey forms was officially published, highlighting the SSRF risk.
Redpacketsecurity
2026-09-17
Vulnerability reported by multiple sources
Both Redpacketsecurity and Vulncheck reported on the CVE, detailing its implications and risks.
Vulncheck

More articles in this cluster (3)

Following this threat?

Track CVE-2026-92602 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed