Jul 2026
Description
A vulnerability was identified in the authentication mechanism that allows user enumeration through the login interface. An attacker can differentiate between valid and invalid usernames based on variations in server responses. This information can be leveraged to identify existing accounts and facilitate further attacks, including brute-force or credential stuffing.
Details
- Product: docuForm FSM Server
- Affected Versions: 11.11c
- Vulnerability Type: CWE-204: Observable Response Discrepancy
- Risk Level: Medium - CVSS 3.1: 5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
- Vendor URL: www.docuform.de
- CVE: CVE-2026-51926
Impact
An attacker can exploit this vulnerability to enumerate valid usernames through the login interface by observing differences in error messages for valid versus invalid usernames. This information disclosure can be used to compile a list of active accounts, which may facilitate targeted brute‑force, credential‑stuffing or social‑engineering attacks against identified users.
References
Timeline
- 2025-10: Vulnerability reported to the vendor.
- 2025-11: Vendor published a fix for the issue.
- 2026-06: Information about the vulnerability is published.
Credits
- Bastian Recktenwald (Bastian.Recktenwald@ZeroBreach.de)
