CVE-2026-51924

8.1

docuForm GmbH · Client

A remote code execution vulnerability in docuForm GmbH Client v.11.11c via report.php and file upload functions.

Executive summary

A high-severity remote code execution vulnerability in docuForm GmbH Client allows authenticated attackers to compromise confidentiality and integrity.

Vulnerability

This vulnerability involves improper handling within the file upload and report.php components, allowing a remote attacker with low privileges to achieve arbitrary code execution.

Business impact

A successful exploit permits an attacker to execute arbitrary code with the privileges of the application, leading to severe data compromise and loss of system integrity. With a CVSS score of 8.1, the high severity rating underscores the critical nature of potential unauthorized access and administrative manipulation within the network.

Remediation

Immediate Action: Contact docuForm GmbH to obtain the latest security updates or patches for version 11.11c, and restrict network access to the report.php component.

Proactive Monitoring: Monitor web server access logs for anomalous file upload attempts and unusual HTTP requests targeting report.php.

Compensating Controls: Implement a Web Application Firewall rule to inspect file uploads and block suspicious traffic directed at the vulnerable component.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Security teams must prioritize reaching out to the vendor for a resolution while enforcing strict access controls around the affected application. Immediate containment steps, such as monitoring and filtering traffic, are essential to mitigate the risk of unauthorized code execution.

More docuForm GmbH CVEs

Sources