Junglewise Threat Intelligence

CVE-2026-18723: diaowen DWSurvey improper authorization in survey status handler

CVE-2026-18723 · Severity: medium · CVSS 6.3 · Published 2026-08-04

Technologies: Diaowen DWSurvey. Vendors: Diaowen.

Executive brief

DWSurvey is a survey management application used to create and distribute online surveys. A flaw in the survey status update endpoint allows an attacker to bypass authorization controls and modify survey status without proper permissions, potentially exposing survey data or disrupting legitimate survey operations.

Technical details

An improper authorization vulnerability exists in the survey status handler component, specifically in the /api/dwsurvey/app/survey/up-survey-status.do endpoint. The vulnerability allows an attacker to perform unauthorized manipulation of survey status by exploiting insufficient authorization checks. The attack is network-accessible and does not require authentication or user interaction. An attacker can remotely invoke the vulnerable function to modify survey statuses across the application. The exploit has been publicly disclosed. Patch availability from the vendor is unknown; early disclosure attempts did not result in vendor response.

Affected products

  • diaowen DWSurvey up to 6.14.0

Timeline

  • 2026-08-04: disclosed: Public disclosure; vendor did not respond to early notification

References

Related threats