{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3amenuluxmenulux_portal/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:menulux:menulux_portal:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-19051"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Menulux Portal (\u003c 20260903211448)"],"_cs_severities":["high"],"_cs_tags":["reconnaissance","vulnerability","web-application"],"_cs_type":"advisory","_cs_vendors":["Menulux Software Inc."],"content_html":"\u003cp\u003eMenulux Software Inc. has disclosed a security vulnerability affecting the Menulux Portal application (CVE-2026-19051). The vulnerability involves the insecure, plaintext storage of user passwords within the application's data management systems. This flaw allows an attacker or a malicious insider with access to the underlying data stores or application backups to retrieve sensitive authentication credentials without the need for decryption or credential cracking. The issue affects all versions of Menulux Portal released prior to 20260903211448. Organizations relying on this portal for credential management should prioritize patching to the latest version to prevent unauthorized access to sensitive account information.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability leads to the exposure of plaintext credentials for users of the Menulux Portal. This poses a significant risk to the confidentiality of user accounts and may facilitate unauthorized access to the portal or other systems where users have reused passwords. As this vulnerability relates to the fundamental storage of credentials, the impact is systemic for the affected platform.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the immediate update of all Menulux Portal instances to version 20260903211448 or later. Following the update, security teams should audit existing database and backup files for previously stored plaintext credentials and enforce a mandatory password reset for all users identified in the exposed datasets.\u003c/p\u003e\n","date_modified":"2026-09-04T13:25:28Z","date_published":"2026-09-04T13:25:18Z","id":"https://feed.craftedsignal.io/briefs/2026-09-menulux-plaintext-passwords/","summary":"Menulux Portal versions before 20260903211448 contain a vulnerability that stores passwords in plaintext, potentially allowing unauthorized retrieval of sensitive credentials.","title":"Plaintext Password Storage Vulnerability in Menulux Portal","url":"https://feed.craftedsignal.io/briefs/2026-09-menulux-plaintext-passwords/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:menulux:menulux_portal:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}