AUGUST 24, 2026
Live Feed
Back to database
Case File

CVE-2026-51926

HIGH · CVSS 7.5 EPSS 0.36% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-09 · Last synced 2026-08-08

CyberRota Analysis

AI-Generated

The vulnerability in docuForm GmbH FSM Client v.11.11c exposes the login.php component, allowing remote attackers to perform user enumeration through inconsistent server responses. This flaw enables attackers to identify valid usernames, which can be exploited for subsequent attacks such as brute-force or credential stuffing. Organizations using this software should prioritize remediation to protect sensitive user information and prevent unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-51926
Severity
HIGH
CVSS
7.5
EPSS
0.36%

Original NVD Description

An issue in docuForm GmbH FSM Client v.11.11c allows a remote attacker to obtain sensitive information via the login.php component. A vulnerability was identified in the authentication mechanism that allows user enumeration through the login interface. An attacker can differentiate between valid and invalid usernames based on variations in server responses. This information can be leveraged to identify existing accounts and facilitate further attacks, including brute-force or credential stuffing.