CVE-2026-51923
the affected product
An Insecure Direct Object Reference (IDOR) vulnerability exists in docuForm GmbH Client v.11.11c allowing a remote attacker to execute arbitrary code via the user settings component, and modify or retrieve sensitive data associated with other users’ accounts.
- CVSS
- 8.1
- EPSS
- 0.38% 30.8% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.10