Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-75325: DWSurvey 6.14.0 allows attackers to skip login
CVE-2026-75325 · published 8 days ago
Summary
The DWSurvey version 6.14.0 web tool can be tricked into granting access without proper login through certain web addresses. This could let unauthorized users view or change survey data. Apply the latest software update or restrict access to those URLs until a fix is installed.
Original advisory text
DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '/api/dwsurvey/up/**' parameters.
DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '/api/dwsurvey/up/**' parameters.
Severity
9.8
Critical
Exploitation
EPSS <1%
Type
CWE-287Improper Authentication
Timeline
Published26 Aug 2026
Updated30 Aug 2026
First seen26 Aug 2026
Monitor software like this
Free during beta