Junglewise Threat Intelligence

CVE-2026-51923: docuForm FSM Server IDOR in user management

CVE-2026-51923 · Severity: info · CVSS 8.1 · Published 2026-07-09

Technologies: docuForm FSM Server. Vendors: docuForm.

Executive brief

A security vulnerability exists in docuForm FSM Server, a document and print process management solution. An attacker with a standard user account can exploit this flaw to access or modify sensitive information belonging to other users. This could lead to a full account takeover, compromising the privacy and integrity of document workflows.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability (CWE-639) exists in the user management functionality of docuForm FSM Server v.11.11c. The application fails to properly validate authorization when a user-controlled key is used to access account settings or data. A remote, authenticated attacker can exploit this by manipulating identifiers in requests to view or modify sensitive information belonging to other users. This can result in unauthorized data disclosure or full account takeover. While the NVD summary mentions arbitrary code execution, the primary researcher's technical documentation (ZeroBreach) classifies this specific CVE as an IDOR leading to account takeover, with a CVSS 3.1 score of 8.1.

Affected products

  • docuForm GmbH FSM Server 11.11c

Timeline

  • 2026-07-01: disclosed: Vulnerability details published by researcher ZeroBreach-GmbH
  • 2026-07-09: advisory: CVE published in the National Vulnerability Database (NVD)

References

Related threats