Medium severity5.3NVD Advisory· Published Oct 2, 2020· Updated Jun 17, 2026
CVE-2020-26526
CVE-2020-26526
Description
An issue was discovered in Damstra Smart Asset 2020.7. It is possible to enumerate valid usernames on the login page. The application sends a different server response when the username is invalid than when the username is valid ("Unable to find an APIDomain" versus "Wrong email or password").
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- cpe:2.3:a:damstratechnology:smart_asset:2020.7:*:*:*:*:*:*:*
(expand)+ 1 more
- (no CPE)
- (no CPE)range: = 2020.7
- Range: = 2020.7
Patches
Vulnerability mechanics
References
2- smartasset.comnvdVendor Advisory
- support.damstratechnology.com/hc/en-us/categories/900000115446-SmartAsset-Damstra-Asset-Management-PlatformnvdVendor Advisory
News mentions
0No linked articles in our index yet.