CVE-2026-86778: Username Enumeration in Maksisoft Technology's Maksisoft Gym
Published Sep 30, 2026
·Updated
Observable response discrepancy vulnerability in Maksisoft Technology, IT, and Software Industry and Trade Inc. Maksisoft Gym allows Account Footprinting.
This issue affects Maksisoft Gym: from 0.5.10 before 0.5.11.
Affected Software
1 affected component
Maksisoft Technology Maksisoft Gym>=0.5.10<0.5.11
Event History
Sep 30, 2026
CVE Published
via MITRE·12:59 PM
Data Sourced
via MITRE·12:59 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What can an unauthenticated attacker learn from this issue?
An attacker can use observable differences in responses to determine whether usernames or accounts exist, enabling account footprinting.
2
Which deployments are affected?
Maksisoft Gym versions from 0.5.10 up to, but not including, 0.5.11 are affected.