CVE-2025-8756 | TDuckCloud tduck-platform up to 5.1 /manage/ preHandle improper authorization (Issue 28 / EUVD-2025-24054)
A vulnerability was found in TDuckCloud tduck-platform up to 5.1 and classified as critical. The impacted element is the function preHandle of the file /manage/ of the component com.tduck.cloud.api.web.interceptor.AuthorizationInterceptor. The manipulation results in improper authorization.
This vulnerability is known as CVE-2025-8756. It is possible to launch the attack remotely. Furthermore, an exploit is available.