CVE-2026-53908
MCO is vulnerable to User Enumeration through authentication-related functionalities. The application returns distinguishable responses for
CVSS
4.3
Medio
EPSS
0.4%
p30
KEV
—
Exploit Today
9
0-100
Publicado: 1 jul 2026 · Última mod.: 6 jul 2026 · CWE-204
0.2%EPSS · 30 días0.4%
2026-08-202026-09-17
MCO is vulnerable to User Enumeration through authentication-related functionalities. The application returns distinguishable responses for valid and invalid users during username reminder and password reset operations. An attacker can leverage these differences to enumerate valid usernames and email addresses. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 25.3.3.1 but may also affect other versions.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-891735.3 MED18.1%
——5Smart Video Intercom System developed by Kingdom Communication Associated has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can enumerate valid user accounts by exploiting differences in system responses.7dCVE-2026-91615.3 MED9.8%
——3Observable response discrepancy vulnerability in DernekPlus Website Template allows Account Footprinting.
This issue affects Website Template: through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.8dCVE-2026-867586.5 MED15.3%
——5Snipe-IT before 8.7.0 fails to properly enforce the viewKeys authorization gate in CSV export and API index endpoints, allowing authenticated users with only licenses.view permission to access product keys. Attackers can download all license keys in bulk via CSV export or validate candidate keys through API response discrepancies without needing the viewKeys permission.2dCVE-2026-192057.5 ALT15.9%
——5Observable response discrepancy vulnerability in GastroMenum GastroMenum Web Panel allows Account Footprinting.
This issue affects GastroMenum Web Panel: before 31.08.2026.10dCVE-2026-190807.5 ALT23.0%
——7Observable response discrepancy vulnerability in Menulux Software Inc. Menulux Portal allows Account Footprinting.
This issue affects Menulux Portal: before 20260903211448.10dCVE-2026-785844.3 MED13.4%
——4Observable Response Discrepancy (CWE-204) in the Kibana Osquery feature can lead to information disclosure via Query System for Information (CAPEC-54). An authenticated user holding Osquery live-query privileges could determine whether a scheduled query identifier exists in a Kibana space they are not authorized to access.15d