{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/mobile-app--2026-05-12/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-2346"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Mobile App (\u003c= 2026-05-12)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Menulux Software Inc."],"content_html":"\u003cp\u003eCVE-2026-2346 is a critical vulnerability identified in the Menulux Mobile App, documented by the Computer Emergency Response Team of the Republic of Turkey. The flaw involves an authorization bypass mechanism based on a user-controlled key (CWE-639). This vulnerability allows an unauthenticated, remote attacker to bypass existing security controls within the application. By manipulating the user-controlled key, an attacker can achieve unauthorized access or perform actions that impact the integrity of the software. The issue affects all versions of the Menulux Mobile App up to and including the version released on May 12, 2026. Given the CVSS 3.1 base score of 9.8, this vulnerability poses a significant risk to the security and operational integrity of the affected mobile environments.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability results in a complete authorization bypass, enabling attackers to perform unauthorized actions within the application context. This may lead to unauthorized data access, modification of application settings, or a broader software integrity attack. Organizations utilizing the affected version of the Menulux Mobile App are at risk of unauthorized administrative or user-level actions, which could compromise the entire deployment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately audit all instances of the Menulux Mobile App within the environment and identify versions released on or before May 12, 2026.\u003c/li\u003e\n\u003cli\u003eContact Menulux Software Inc. to obtain the latest security updates and patches that address CVE-2026-2346.\u003c/li\u003e\n\u003cli\u003eRestrict network access to mobile devices running the vulnerable application if patching cannot be performed immediately.\u003c/li\u003e\n\u003cli\u003eMonitor for any anomalous API calls or unauthorized privilege escalation events associated with mobile device communication to backend services.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-03T14:03:21Z","date_published":"2026-08-03T14:03:21Z","id":"https://feed.craftedsignal.io/briefs/2026-08-menulux-auth-bypass/","summary":"CVE-2026-2346 is a critical authorization bypass vulnerability (CWE-639) in the Menulux Mobile App allowing unauthenticated attackers to manipulate user-controlled keys and compromise software integrity.","title":"Authorization Bypass Vulnerability in Menulux Mobile App","url":"https://feed.craftedsignal.io/briefs/2026-08-menulux-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Mobile App (\u003c= 2026-05-12)","version":"https://jsonfeed.org/version/1.1"}