Description
Observable response discrepancy vulnerability in GastroMenum GastroMenum Web Panel allows Account Footprinting.

This issue affects GastroMenum Web Panel: before 31.08.2026.
Published: 2026-09-04
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Observable differences in the HTTP responses of the GastroMenum Web Panel expose the existence of user accounts, enabling attackers to perform account footprinting. The vulnerability arises from insufficient validation of query parameters that determine whether an account exists. Successful exploitation allows an attacker to enumerate valid usernames, thereby facilitating targeted credential‑guessing or social‑engineering campaigns, which can compromise confidentiality of user identities and potential access to sensitive resources.

Affected Systems

All installations of GastroMenum Web Panel with versions prior to 31.08.2026 are affected. The vulnerability is documented for the product line managed by GastroMenum, and no earlier patch versions have mitigated this flaw.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity. The exploit probability is not quantified in the EPSS data, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the attack vector is inferred to be remote, reachable via the publicly exposed web interface. Because the weakness falls under CWE-204, attackers gain sensitive information through reference handling in the application. No additional exploitation prerequisites are described, implying that an unauthenticated client can trigger the enumeration by observing response differences.

Generated by OpenCVE AI on September 4, 2026 at 15:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade GastroMenum Web Panel to version 31.08.2026 or later to apply the vendor fix
  • Reconfigure the web panel to return generic response messages for all authentication attempts, eliminating response discrepancies that reveal account existence
  • Enable audit logging for authentication requests and set up alerts for repeated failed user lookup attempts to detect enumeration activities

Generated by OpenCVE AI on September 4, 2026 at 15:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description Observable response discrepancy vulnerability in GastroMenum GastroMenum Web Panel allows Account Footprinting. This issue affects GastroMenum Web Panel: before 31.08.2026.
Title User Enumeration in GastroMenum's GastroMenum Web Panel
Weaknesses CWE-204
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-09-04T14:08:37.890Z

Reserved: 2026-08-07T07:53:00.212Z

Link: CVE-2026-19205

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-04T15:17:33.360

Modified: 2026-09-04T15:17:33.360

Link: CVE-2026-19205

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T16:00:05Z

Weaknesses
  • CWE-204

    Observable Response Discrepancy