A user enumeration vulnerability exists in FormaLMS 4.1.18 and below in the password recovery functionality accessible via the /lostpwd endpoint. The application returns different error messages for valid and invalid usernames allowing an unauthenticated attacker to determine which usernames are registered in the system through observable response discrepancy.
References
| Link | Resource |
|---|---|
| https://github.com/formalms/formalms.git | Product |
| https://github.com/lorenzobruno7/CVE-2026-26744 | Third Party Advisory |
Configurations
History
26 Feb 2026, 02:48
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/formalms/formalms.git - Product | |
| References | () https://github.com/lorenzobruno7/CVE-2026-26744 - Third Party Advisory | |
| CPE | cpe:2.3:a:formalms:formalms:*:*:*:*:*:*:*:* | |
| First Time |
Formalms formalms
Formalms |
24 Feb 2026, 17:29
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
|
| CWE | CWE-204 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
19 Feb 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-19 22:16
Updated : 2026-02-26 02:48
NVD link : CVE-2026-26744
Mitre link : CVE-2026-26744
CVE.ORG link : CVE-2026-26744
JSON object : View
Products Affected
formalms
- formalms
CWE
CWE-204
Observable Response Discrepancy
