EIP-2026-102396
PRE-CVELogicalDOC Enterprise 7.7.4 - User Enumeration
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-102396. PoCs published by LiquidWorm.
AI-analyzed exploit summary The document describes a username enumeration vulnerability in LogicalDOC Enterprise versions 7.7.4 and below, where the 'j_spring_security_check' endpoint returns different HTTP responses for valid and invalid usernames, allowing attackers to enumerate valid users.
Description
LogicalDOC Enterprise 7.7.4 - User Enumeration
Exploits (1)
exploitdb
WRITEUP
by LiquidWorm · textwebappsjava
https://www.exploit-db.com/exploits/44020
The document describes a username enumeration vulnerability in LogicalDOC Enterprise versions 7.7.4 and below, where the 'j_spring_security_check' endpoint returns different HTTP responses for valid and invalid usernames, allowing attackers to enumerate valid users.
Classification
Writeup 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target:
LogicalDOC Enterprise 7.7.4 and below
No auth needed
Prerequisites:
Network access to the target application
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026