A vulnerability, which was classified as critical, was found in diaowen DWSurvey up to 6.14.0. Impacted is the function
in DwDeisgnSurveyController.devSurvey. of the file /api/dwsurvey/app/v6/dw-design-survey/dev-survey.do of the component Survey Handler. The manipulation results in authorization bypass.
This vulnerability is reported as CVE-2026-18722. The attack can be launched remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.