What is CVE-2026-18722?
An authorization bypass vulnerability has been identified in diaowen DWSurvey up to version 6.14.0, affecting the Survey Handler component via the /api/dwsurvey/app/v6/dw-design-survey/dev-survey.do file. The flaw in the "DwDeisgnSurveyController.devSurvey" function could allow remote attackers to perform unauthorized operations on surveys. Users are advised to update to the latest version immediately.
Azərbaycanca: DWSurvey platformasında (6.14.0 və əvvəlki versiyalar) "Survey Handler" komponentində yerləşən /api/dwsurvey/app/v6/dw-design-survey/dev-survey.do faylında avtorizasiya bypass zəifliyi aşkar edilib. Bu, uzaqdan hücum edənə "DwDeisgnSurveyController.devSurvey" funksiyası vasitəsilə sorğu anketləri üzərində icazəsiz əməliyyatlar aparmağa imkan verə bilər. İstifadəçilərə dərhal proqram təminatını ən son versiyaya yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of DWSurvey are affected by CVE-2026-18722?
Versions up to 6.14.0 are affected.
In which component of DWSurvey does CVE-2026-18722 reside?
It resides in the Survey Handler component, specifically in the /api/dwsurvey/app/v6/dw-design-survey/dev-survey.do file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.