Description
An issue in docuForm GmbH FSM Client v.11.11c allows a remote attacker to obtain sensitive information via the login.php component. A vulnerability was identified in the authentication mechanism that allows user enumeration through the login interface. An attacker can differentiate between valid and invalid usernames based on variations in server responses. This information can be leveraged to identify existing accounts and facilitate further attacks, including brute-force or credential stuffing.
Published: 2026-07-09
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

docuForm GmbH FSM Client 11.11c contains a flaw in the login.php authentication routine that allows a remote attacker to observe differences in server responses for valid versus invalid usernames, thereby enabling user enumeration. The weakness, classified as CWE‑203, permits the attacker to discover existing account names and can aid in further attacks such as credential stuffing or brute‑force attempts, effectively compromising user confidentiality.

Affected Systems

All deployments of docuForm GmbH FSM Client 11.11c that expose the login.php endpoint over a network are affected. If the web interface is publicly reachable, the vulnerability applies to any instance using this version.

Risk and Exploitability

The flaw is accessed via a remote web interface, requiring only network connectivity to the affected server. With a CVSS score of 7.5 and an EPSS score of < 1%, the likelihood of exploitation is currently low. The vulnerability is not listed in CISA’s KEV catalog, so no publicly known exploit exists. Nonetheless, an attacker can use the enumeration capability as a stepping stone to further compromise user accounts or downstream services.

Generated by OpenCVE AI on July 25, 2026 at 20:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply an official patch or upgrade to a newer release of docuForm FSM Client that addresses the login.php enumeration issue when one becomes available.
  • Restrict inbound traffic to the login.php endpoint by limiting access to trusted IP ranges or network segments.
  • Configure the application to return uniform response messages and timing for both valid and invalid usernames to eliminate observable side‑channel differences.

Generated by OpenCVE AI on July 25, 2026 at 20:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 25 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title User enumeration via differential responses in docuForm FSM Client login

Wed, 22 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Login.php User Enumeration in docuForm FSM Client 11.11c

Thu, 16 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Login.php User Enumeration in docuForm FSM Client 11.11c

Tue, 14 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title DocuForm FSM Client 11.11c Login Endpoint Allows User Enumeration and Sensitive Information Disclosure

Mon, 13 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title DocuForm FSM Client 11.11c Login Endpoint Allows User Enumeration and Sensitive Information Disclosure

Sun, 12 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title User Enumeration via login.php Leading to Sensitive Information Exposure
Weaknesses CWE-1696

Fri, 10 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-203
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title User Enumeration via login.php Leading to Sensitive Information Exposure
Weaknesses CWE-1696

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Docuform
Docuform client
Vendors & Products Docuform
Docuform client

Thu, 09 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Description An issue in docuForm GmbH FSM Client v.11.11c allows a remote attacker to obtain sensitive information via the login.php component. A vulnerability was identified in the authentication mechanism that allows user enumeration through the login interface. An attacker can differentiate between valid and invalid usernames based on variations in server responses. This information can be leveraged to identify existing accounts and facilitate further attacks, including brute-force or credential stuffing.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-10T15:35:04.919Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51926

cve-icon Vulnrichment

Updated: 2026-07-10T15:33:19.605Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-25T20:45:02Z

Weaknesses