CVE-2026-51926

An issue in docuForm GmbH FSM Client v.11.11c allows a remote attacker to obtain sensitive information via the login.php component. A vulnerability was identified in the authentication mechanism that allows user enumeration through the login interface. An attacker can differentiate between valid and invalid usernames based on variations in server responses. This information can be leveraged to identify existing accounts and facilitate further attacks, including brute-force or credential stuffing.
Configurations

No configuration.

History

10 Jul 2026, 17:16

Type Values Removed Values Added
CWE CWE-203
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

09 Jul 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-09 21:16

Updated : 2026-07-10 18:53


NVD link : CVE-2026-51926

Mitre link : CVE-2026-51926

CVE.ORG link : CVE-2026-51926


JSON object : View

Products Affected

No product.

CWE
CWE-203

Observable Discrepancy