ZeroHour

CVE-2026-19205

Account Footprinting via Response Discrepancy in GastroMenum Web Panel

CVSS 3.1
7.5 high
EPSS
<1%p16
Published
()
Modified
AI analysis

CVE-2026-19205 is an observable response discrepancy (CWE-204) in GastroMenum Web Panel: the application replies differently depending on whether an account exists, typically on unauthenticated pages such as the sign-in flow. A network attacker needs no credentials or user interaction and can trigger the flaw simply by probing the panel with candidate account names and comparing the responses. The result is account footprinting — the attacker learns which accounts/usernames are valid — which the CVSS score rates as high confidentiality impact (C:H) with no integrity or availability impact, yielding a target list for follow-on credential-guessing attacks. Any deployment of GastroMenum Web Panel older than the 31.08.2026 release is affected, particularly panels reachable from the internet. There is currently no known public proof-of-concept, no entry in CISA KEV, and a low EPSS (0.2%, 16th percentile), indicating no confirmed exploitation in the wild.

What to do: Upgrade GastroMenum Web Panel to the 31.08.2026 (August 31, 2026) release or later. Until patched, reduce exposure of the panel (IP allowlisting/VPN or firewall restrictions) and consider rate-limiting or normalizing authentication responses via a reverse proxy/WAF to blunt enumeration attempts. Review access logs for bursts of sign-in or username-probing requests from unknown sources.

Affected
GastroMenum Web Panelall versions before 31.08.2026 (fixed in the 31.08.2026 release)
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Observable response discrepancy vulnerability in GastroMenum GastroMenum Web Panel allows Account Footprinting. This issue affects GastroMenum Web Panel: before 31.08.2026.

Weakness
CWE-204
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.