CVE-2026-51923

High severity, CVSS 8.1. EPSS: 0.7% chance of exploitation in the next 30 days.

An Insecure Direct Object Reference (IDOR) vulnerability exists in docuForm GmbH Client v.11.11c allowing a remote attacker to execute arbitrary code via the user settings component, and modify or retrieve sensitive data associated with other users’ accounts.

Published 2026-07-09. Last modified 2026-07-10.