CVE-2026-86778
Received
Received - Intake
Observable Response Discrepancy in Maksisoft Gym Allows Account Footprinting
Vulnerability report for CVE-2026-86778, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-30
Last updated on: 2026-09-30
Assigner: Computer Emergency Response Team of the Republic of Turkey
Description
Description
Observable response discrepancy vulnerability in Maksisoft Technology, IT, and Software Industry and Trade Inc. Maksisoft Gym allows Account Footprinting.
This issue affects Maksisoft Gym: from 0.5.10 before 0.5.11.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| maksisoft | gym | From 0.5.10 (inc) to 0.5.11 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-204 | The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere. |