Description
Missing Authorization vulnerability in Gastromenum Gastromenum Ticket and QR Menu System allows Accessing Functionality Not Properly Constrained by ACLs.

This issue affects Gastromenum Ticket and QR Menu System: before 2026.08.31.
Published: 2026-09-04
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw that allows an attacker to invoke critical POS operations without proper access control. Because the flaw is not limited to a single function, a compromised user or an external threat could gain access to functions that should be protected by ACLs, potentially leading to financial loss, data tampering, or disruption of point‑of‑sale operations.

Affected Systems

Gastromenum Ticket and QR Menu System installed on any system before 2026.08.31 is affected. The flaw is present in versions older than the 2026.08.31 release, and the vendor has not provided a fix or workaround for these versions.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate risk level. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog, so the current exploit probability is uncertain. The likely attack vector is inferred to be through the web or POS interface where the ACLs are bypassed; however, the exact conditions for exploitation are not fully detailed in the public description.

Generated by OpenCVE AI on September 4, 2026 at 15:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Gastromenum Ticket and QR Menu System version 2026.08.31 or later once a vendor‑issued patch is available.
  • Restrict critical POS functions with explicit ACL checks so that only authorized accounts can access them, following the guidance for CWE‑862.
  • Apply network segmentation so that POS systems are isolated from external networks, limiting potential exploitation routes.
  • Implement log monitoring for anomalous use of critical POS functions to detect unauthorized activity early.

Generated by OpenCVE AI on September 4, 2026 at 15:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Gastromenum Gastromenum Ticket and QR Menu System allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Gastromenum Ticket and QR Menu System: before 2026.08.31.
Title Missing Authorization Allows Unauthorized Access to Critical POS Functions in Gastromenum's Gastromenum Ticket and QR Menu System
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-09-04T13:57:55.260Z

Reserved: 2026-08-06T11:35:49.643Z

Link: CVE-2026-19081

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-04T14:17:18.193

Modified: 2026-09-04T14:17:18.193

Link: CVE-2026-19081

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T16:00:05Z

Weaknesses