Description
An Insecure Direct Object Reference (IDOR) vulnerability exists in docuForm GmbH Client v.11.11c allowing a remote attacker to execute arbitrary code via the user settings component, and modify or retrieve sensitive data associated with other users’ accounts.
Published: 2026-07-09
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An insecure direct object reference flaw in the user settings component of DocuForm GmbH Client 11.11c allows a remote attacker to execute arbitrary code and access or alter other users’ sensitive data. The vulnerability stems from insufficient validation of object identifiers, enabling unauthorized actions via the client’s UI or internal API calls. When exploited, it compromises confidentiality, integrity, and availability for the affected accounts.

Affected Systems

DocuForm GmbH Client, version 11.11c, is the only version identified as vulnerable. The flaw specifically targets the user settings component within this product.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity, whereas the EPSS score of less than 1% suggests a low likelihood of active exploitation. The vulnerability is not listed in CISA KEV, which further reduces concern for widespread current exploitation. The description of the vulnerability states remote exploitation via the user settings component, but no public web interface or API is mentioned; thus the attack vector is inferred to be through the client’s UI or an internal API, likely needing authenticated access. Given the absence of publicly available exploits and a low EPSS, the immediate risk is limited but the potential impact warrants swift remediation.

Generated by OpenCVE AI on August 3, 2026 at 04:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a patched version of DocuForm Client.
  • Disable or restrict the remote user‑settings endpoint until a patch is available.
  • Enforce strict access controls so that only the owning user can view or modify settings, mitigating the CWE‑639 weakness.

Generated by OpenCVE AI on August 3, 2026 at 04:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title IDOR in DocuForm Client Enables Remote Code Execution

Thu, 23 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title IDOR in DocuForm Client Enables Remote Code Execution

Tue, 21 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title IDOR in DocuForm Client Enables Remote Code Execution

Wed, 15 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title IDOR in DocuForm Client Enables Remote Code Execution

Tue, 14 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title IDOR Enables Remote Code Execution in DocuForm Client

Mon, 13 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title IDOR Enables Remote Code Execution in DocuForm Client

Sun, 12 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title Insecure Direct Object Reference Allows Remote Code Execution and Data Access in DocuForm Client

Fri, 10 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Insecure Direct Object Reference Allows Remote Code Execution and Data Access in DocuForm Client
Weaknesses CWE-639

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Docuform
Docuform client
Vendors & Products Docuform
Docuform client

Thu, 09 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Description An Insecure Direct Object Reference (IDOR) vulnerability exists in docuForm GmbH Client v.11.11c allowing a remote attacker to execute arbitrary code via the user settings component, and modify or retrieve sensitive data associated with other users’ accounts.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-10T15:32:15.156Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51923

cve-icon Vulnrichment

Updated: 2026-07-10T15:31:52.443Z

cve-icon NVD

Status : Deferred

Published: 2026-07-09T21:16:55.480

Modified: 2026-07-10T18:51:16.090

Link: CVE-2026-51923

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T04:45:03Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key