CVE-2026-2346

Umgehung der Autorisierung durch Schwachstelle im benutzerkontrollierten Schlüssel bei Menulux Software Inc (CVE-2026-2346)

criticalEPSS 0.3 %

Beschreibung

Umgehung der Autorisierung durch Schwachstelle im benutzerkontrollierten Schlüssel bei Menulux Software Inc. Mobile App ermöglicht Angriff auf die Integrität des Programms. Dieses Problem betrifft die Mobile App: bis einschließlich 12.05.2026.

Quelle: CVELISTV5NVD

Metriken

Severity
critical
kein öffentlicher PoC bekannt
9.8
Quelle: nvd-v3
20.8 %
Erhöht — CVE ist relevanter als mindestens 10 % der heute bewerteten CVEs.
0.3 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-08-03 11:49 UTC
CWE-639

Weakness-Klassen (CWE)

  • CWE-639Base

    Authorization Bypass Through User-Controlled Key

    The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-08-03 14:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-2346","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalI…
  2. New CVE Received2026-08-03 13:17 UTC· iletisim@usom.gov.tr
    • Affected: Mobile App
    • Description: Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc. Mobile App allows Software Integrity Attack. This issue affects Mobile App: through 12.05.2026.
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    • CWE: CWE-639

Quellen & Referenzen

Verknüpfte Empfehlungen

IDCVE-2026-2346