Sceawere

Vulnerability Detail

CVE-2026-86778UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Maksisoft Gym Account Footprinting

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
3h ago
Vendor
Maksisoft Technology, IT, and Software…
Product
Maksisoft Gym
Attack Type
CWE-204 Observable response discrepancy
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Observable response discrepancy vulnerability in Maksisoft Technology, IT, and Software Industry and Trade Inc. Maksisoft Gym allows Account Footprinting. This issue affects Maksisoft Gym: from 0.5.10 before 0.5.11.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-09-30T13:17:21.207Z",
  "pubdate": "2026-09-30T13:17:21.207Z",
  "executiveSummary": "Maksisoft Gym, within the range of version 0.5.10 before 0.5.11, is susceptible to an observable response discrepancy vulnerability that facilitates account footprinting.\nThis vulnerability allows an unauthorized actor to determine the existence of specific user accounts within the system by analyzing disparities in application responses.\nBy observing differences in error messages, status codes, or response timings during authentication or password reset procedures, an attacker can confirm valid usernames.\nThis information disclosure vulnerability poses a significant risk to user privacy and security, as it provides a reconnaissance mechanism for further targeted attacks, such as credential stuffing or brute-force attacks.\nThe vulnerability is inherent to the application's response logic, which fails to consistently treat legitimate and non-existent account attempts, thereby leaking user enumeration data.",
  "technicalDetails": "The vulnerability manifests as an observable response discrepancy, a common class of information disclosure flaws where the application reveals sensitive system state information—in this case, user account validity—based on the discrepancy between responses for valid versus invalid input.\nIn the context of Maksisoft Gym versions 0.5.10 to 0.5.11 (exclusive), the authentication or account verification logic fails to implement a uniform response mechanism for unsuccessful login attempts or password recovery requests.\nWhen an attacker submits a username during a login or password reset flow, the application's backend logic dictates a specific execution path based on whether the account is registered in the database. If the account does not exist, the application may return a distinct HTTP status code, a specific error message (e.g., 'User not found' vs. 'Incorrect password'), or exhibit a variation in response latency due to the absence of subsequent computational or database operations that would normally occur for a valid user.\nThe attack flow proceeds as follows: First, the attacker identifies the input vector used for account validation, such as a login endpoint or a 'forgot password' feature. Second, the attacker prepares a list of target usernames or systematically iterates through potential usernames. Third, for each candidate, the attacker observes the application's response characteristics. If the application returns a specific indicator confirming the user does not exist, the attacker eliminates that candidate. If the application response differs, implying the user might exist, the attacker confirms the validity of that account.\nThis enumeration process, known as account footprinting, enables the attacker to build a list of confirmed user accounts, significantly reducing the search space for subsequent brute-force or credential stuffing attacks against authenticated endpoints.\nThe vulnerability is exploitable remotely over the network without requiring prior authentication. Because it relies on the application's response design, no special privileges are required, and the attack can be automated to rapidly enumerate a large user base."
}
CVE-2026-86778: Maksisoft Gym Account Footprinting (MEDIUM Severity, CVSS: 5.3) | Sceawere