Description
Observable response discrepancy vulnerability in Menulux Software Inc. Menulux Portal allows Account Footprinting.

This issue affects Menulux Portal: before 20260903211448.
Published: 2026-09-04
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An observable response discrepancy vulnerability in Menulux Portal allows an attacker to discover valid usernames, enabling account discovery and facilitating subsequent credential attacks. The flaw is related to improper resource identification and can expose user existence via differing responses.

Affected Systems

The vulnerability affects Menulux Software Inc.'s Menulux Portal versions prior to 20260903211448, which are deployed in affected environments and have not yet applied the referenced update.

Risk and Exploitability

With a CVSS score of 7.5, this issue is considered high risk, and it is not currently listed in CISA KEV. The EPSS score is not available, but the attack vector is inferred to be remote, exploiting the web interface by sending crafted requests to elicit differing responses based on user validity. If exploited, the attacker could enumerate legitimate accounts and potentially launch phishing or credential stuffing attacks.

Generated by OpenCVE AI on September 4, 2026 at 13:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Menulux Portal release that includes the fix, ensuring the version is after 20260903211448.
  • Configure the portal to return uniform, non-discriminative responses for login attempts, eliminating the response discrepancy that reveals username existence.
  • Monitor web logs for repeated login or enumeration attempts and strengthen any rate‑limiting or throttling policies to reduce the feasibility of enumeration attacks.

Generated by OpenCVE AI on September 4, 2026 at 13:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Menulux
Menulux menulux Portal
Vendors & Products Menulux
Menulux menulux Portal

Fri, 04 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
Description Observable response discrepancy vulnerability in Menulux Software Inc. Menulux Portal allows Account Footprinting. This issue affects Menulux Portal: before 20260903211448.
Title Username Enumeration in Menulux Software's Menulux Portal
Weaknesses CWE-204
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Menulux Menulux Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-09-04T13:18:31.374Z

Reserved: 2026-08-06T11:34:11.058Z

Link: CVE-2026-19080

cve-icon Vulnrichment

Updated: 2026-09-04T13:18:22.130Z

cve-icon NVD

Status : Received

Published: 2026-09-04T12:17:18.443

Modified: 2026-09-04T14:17:18.087

Link: CVE-2026-19080

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T15:19:58Z

Weaknesses
  • CWE-204

    Observable Response Discrepancy