Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/lorenzobruno7/cve-2026-26744
ReconnaissanceVulnerability AnalysisInformation GatheringWeb SecurityPenetration Testing
GitHublorenzobruno7/cve-2026-26744

CVE-2026-26744

Demonstrates user enumeration in FormaLMS via response discrepancy on the /lostpwd endpoint, enabling unauthenticated username discovery for targeted attacks.

View Repository
496 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-26744

A user enumeration vulnerability exists in FormaLMS (4.1.18 and below) in the password recovery functionality accessible via the /lostpwd endpoint. The application returns different error messages for valid and invalid usernames (e.g., "The username you've inserted doesn't exist. Please check and retry." for non-existent users), allowing an unauthenticated attacker to determine which usernames are registered in the system through observable response discrepancy (CWE-204).

This information can be leveraged to conduct targeted brute-force or credential stuffing attacks.

Discovered by Lorenzo Bruno, January 2026.

Download Tool