CVE-2026-51926 Details
Description
An issue in docuForm GmbH FSM Client v.11.11c allows a remote attacker to obtain sensitive information via the login.php component. A vulnerability was identified in the authentication mechanism that allows user enumeration through the login interface. An attacker can differentiate between valid and invalid usernames based on variations in server responses. This information can be leveraged to identify existing accounts and facilitate further attacks, including brute-force or credential stuffing.
A user enumeration vulnerability has been identified in docuForm GmbH FSM Client version 11.11c. This issue allows remote attackers to obtain sensitive information through the login.php component by exploiting variations in server responses. The authentication mechanism fails to adequately obscure the validity of usernames, enabling attackers to distinguish between existing and non-existing accounts. This information can be used to identify valid usernames and facilitate further attacks, such as brute-force or credential stuffing.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 9, 2026CISA-ADP
Assessed Jul 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://docuform.de | [email protected] | Vendor |
| https://gist.github.com/ZeroBreach-GmbH | [email protected] | BundleTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-203 | Observable Discrepancy | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| docuForm FSM Client | 11.11c |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 10, 2026 | CVE Modified | CISA-ADP |
| Jul 9, 2026 | New CVE Received | [email protected] |
Volerion