Jul 2026
Description
An Insecure Direct Object Reference (IDOR) vulnerability exists in the application’s user management functionality that allows an authenticated attacker to modify or retrieve sensitive data associated with other users’ accounts.
Details
- Product: docuForm FSM Server
- Affected Versions: 11.11c
- Vulnerability Type: CWE-639: Authorization Bypass Through User-Controlled Key
- Risk Level: High - CVSS 3.1: 8.1 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N)
- Vendor URL: www.docuform.de
- Vendor acknowledged vulnerability: Yes
- CVE: CVE-2026-51923
Impact
An authenticated attacker who exploits this IDOR‑based vulnerability can gain full control over other users’ accounts, resulting in account takeover.
References
Timeline
- 2025-10: Vulnerability reported to the vendor.
- 2025-11: Vendor published a fix for the issue.
- 2026-06: Information about the vulnerability is published.
Credits
- Bastian Recktenwald (Bastian.Recktenwald@ZeroBreach.de)
