Description
Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc. Mobile App allows Software Integrity Attack.

This issue affects Mobile App: through 12.05.2026.
Published: 2026-08-03
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an IDOR that allows a user-controlled key to bypass authorization checks in Menulux Software Inc.'s Mobile App. The flaw is described as a Software Integrity Attack, indicating that an attacker could potentially read, modify, or execute data and operations that should be protected. The CVSS score of 9.8 demonstrates a severe impact on confidentiality, integrity, and availability, with no authentication or additional mitigations reported in the description.

Affected Systems

Menulux Software Inc. Mobile App versions up to and including 12.05.2026 are affected.

Risk and Exploitability

Because this flaw is accessed via the mobile application, the likely attack vector is local or remote use of the app, possibly through crafted requests or malicious user input. The EPSS score is not available, and the vulnerability is not listed in KEV, yet the high CVSS indicates a significant risk if exploited. Without an official patch details, the risk remains high until remediation is applied.

Generated by OpenCVE AI on August 4, 2026 at 21:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the vendor‑supplied update released after 12.05.2026 to eliminate the IDOR vulnerability.
  • If a patch is not yet available, disable or restrict the application features that depend on user‑controlled keys to prevent unauthorized access.
  • Implement server‑side access‑control and input‑validation mechanisms to reject requests containing unauthorized user‑controlled keys.
  • Log and monitor for anomalous operations involving user keys and implement alerting on suspicious activity.

Generated by OpenCVE AI on August 4, 2026 at 21:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Menulux
Menulux mobile App
Vendors & Products Menulux
Menulux mobile App

Mon, 03 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc. Mobile App allows Software Integrity Attack. This issue affects Mobile App: through 12.05.2026.
Title IDOR in Menulux Software's Mobile App
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Menulux Mobile App
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-08-03T13:17:35.640Z

Reserved: 2026-02-11T15:37:32.943Z

Link: CVE-2026-2346

cve-icon Vulnrichment

Updated: 2026-08-03T13:17:32.299Z

cve-icon NVD

Status : Received

Published: 2026-08-03T13:17:39.513

Modified: 2026-08-03T14:16:26.253

Link: CVE-2026-2346

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T21:15:03Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key