Junglewise Threat Intelligence

CVE-2026-51924: docuForm GmbH FSM Client remote code execution in report.php

CVE-2026-51924 · Severity: info · CVSS 8.8 · Published 2026-07-09

Executive brief

A security vulnerability exists in the docuForm FSM Client, a software component used for managing enterprise printing and document workflows. An attacker with basic user access can exploit this flaw to take full control of the system by running unauthorized commands. This could lead to the theft of sensitive documents, disruption of printing services, or a total compromise of the affected server.

Technical details

A Remote Code Execution (RCE) vulnerability exists in docuForm FSM Client v.11.11c due to improper input validation (CWE-20) within the file upload functionality and the report.php component. By exploiting this flaw, an authenticated attacker can bypass security checks to upload and execute malicious scripts on the underlying server. The attack is reachable over the network and requires low-level user privileges but no user interaction. Successful exploitation grants the attacker the ability to execute arbitrary code with the privileges of the web service, potentially leading to full system compromise.

Affected products

  • docuForm GmbH FSM Client 11.11c

Timeline

  • 2026-07-01: disclosed: Vulnerability details shared by ZeroBreach GmbH via GitHub Gist.
  • 2026-07-09: advisory: CVE published in the NVD dataset.

References