CVE-2025-8756

high
Published 2025-08-09 · Modified 2026-04-29
CVSS v3
8.8
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2
6.5
VIR risk
8.8

Description

A vulnerability has been found in TDuckCloud tduck-platform up to 5.1 and classified as critical. Affected by this vulnerability is the function preHandle of the file /manage/ of the component com.tduck.cloud.api.web.interceptor.AuthorizationInterceptor. The manipulation leads to improper authorization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

Predictions

Exploit likelihood
92%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cna@vuldb.com — https://github.com/TDuckCloud/tduck-platform/issues/28#issue-3269885235

vendor Authored 2026-05-27

Vendor advisory: cna@vuldb.com — https://github.com/TDuckCloud/tduck-platform/issues/28

Application impact

VendorProductVersionsFixed
tduckcloudtduck-platform{"endIncluding":"5.1"}

References

CWEs

CWE-266 CWE-285

Verify integrity in audit chain (admin only). AS-IS.