Description
Missing Authorization vulnerability in Menulux Software Inc. Menulux Portal allows Accessing Functionality Not Properly Constrained by ACLs.

This issue affects Menulux Portal: before 20260903211448.
Published: 2026-09-04
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Menulux Portal is a missing authorization control that allows unauthorized users to access critical POS management functions. Because access‑control lists do not properly constrain these functions, an attacker who obtains valid credentials or exploits a local session could perform actions such as modifying inventory, pricing, or transaction processing without approval. This could lead to financial loss, data tampering, or unauthorized configuration changes, directly impacting the integrity and availability of point‑of‑sale operations.

Affected Systems

The issue is present in all versions of Menulux Portal released before the build identifier 20260903211448. The affected vendor is Menulux Software Inc., and the product is Menulux Portal, a web‑based management interface used by retailers to control POS devices and back‑office functions.

Risk and Exploitability

The CVSS score of 4.3 indicates a lower severity compared to remote code execution vulnerabilities, but the lack of proper ACL enforcement still poses a significant operational risk. EPSS is unavailable, so current exploitation probability cannot be measured; however, the vulnerability is not listed in the CISA KEV catalog, implying no publicly known exploits yet. Likely attack vectors involve authenticated users or compromised accounts within the portal, with the attacker leveraging the exposed function calls directly through the web interface. In the absence of a patch, the risk primarily lies in internal or privileged users abusing the system.

Generated by OpenCVE AI on September 4, 2026 at 13:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Menulux Portal to version 20260903211448 or later to apply the vendor's fix.
  • Configure the portal to enforce proper ACLs on all critical POS functions, ensuring that only authorized roles can access them.
  • Conduct a thorough audit of existing ACLs and user privileges to confirm that no unintended permissions exist, and tighten restrictions accordingly.

Generated by OpenCVE AI on September 4, 2026 at 13:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Menulux
Menulux menulux Portal
Vendors & Products Menulux
Menulux menulux Portal

Fri, 04 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Menulux Software Inc. Menulux Portal allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Menulux Portal: before 20260903211448.
Title Authorization Bypass Critical POS Management Functions in Menulux Software's Menulux Portal
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Menulux Menulux Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-09-04T13:33:02.457Z

Reserved: 2026-08-06T06:58:55.303Z

Link: CVE-2026-19043

cve-icon Vulnrichment

Updated: 2026-09-04T13:32:58.528Z

cve-icon NVD

Status : Received

Published: 2026-09-04T12:17:18.203

Modified: 2026-09-04T14:17:17.760

Link: CVE-2026-19043

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T15:20:02Z

Weaknesses