Executive brief
docuForm FSM is a document and print management solution used to handle corporate printing workflows. A security flaw in the login interface allows unauthorized individuals to determine which usernames are valid by observing differences in how the server responds to login attempts. This information can be used by attackers to target specific accounts for password-guessing attacks or other malicious activities.
Technical details
A user enumeration vulnerability exists in the authentication mechanism of docuForm FSM Client and Server version 11.11c. The flaw is located in the login.php component, where the application exhibits an observable response discrepancy (CWE-204) when processing login requests. A remote, unauthenticated attacker can differentiate between valid and invalid usernames based on variations in server responses. This reconnaissance can be leveraged to harvest valid account names, facilitating subsequent brute-force or credential stuffing attacks. The vulnerability was assigned a CVSS 3.1 base score of 5.3.
Affected products
- docuForm GmbH FSM Client 11.11c
- docuForm GmbH FSM Server 11.11c
Timeline
- 2026-07-01: disclosed: Initial researcher gist published by ZeroBreach GmbH
- 2026-07-09: advisory: CVE published to NVD dataset