CVE-2026-51923

HIGH

docuForm Client 11.11c - Insecure Direct Object Reference and Remote Code Execution via User Settings Component

Title source: llm
STIX 2.1

Description

An Insecure Direct Object Reference (IDOR) vulnerability exists in docuForm GmbH Client v.11.11c allowing a remote attacker to execute arbitrary code via the user settings component, and modify or retrieve sensitive data associated with other users’ accounts.

Scores

CVSS v3 8.1
EPSS 0.0038
EPSS Percentile 30.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-639
Status published
Published Jul 09, 2026
Tracked Since Jul 10, 2026