PatchSiren

TDuckCloud CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH TDuckCloud CVE published 2026-09-16

CVE-2026-92602

CVE-2026-92602 debrief based on the supplied source corpus. The CVE record was published on 2026-09-16T17:18:20.590Z and has not been modified since then. The vulnerability affects TDuck survey form through version 5.3, allowing authenticated attackers to attach webhooks to other users' forms and exfiltrate submissions to arbitrary external or internal addresses due to lack of webhook URL validation and f [truncated]