A critical-severity authorization bypass in Menulux Software Inc.'s Mobile App lets unauthenticated, remote attackers manipulate user-controlled keys to compromise software integrity, scoring a 9.8 CVSS.
What Is It
CVE-2026-2346 is an authorization bypass through a user-controlled key (CWE-639) in Menulux Software Inc.'s Mobile App. The flaw allows a Software Integrity Attack; an attacker supplies or tampers with a key value that the application trusts for authorization decisions, bypassing the intended access controls.
The vulnerability was published on 2026-08-03 and reported by USOM (Turkey's national CERT, [email protected]). Its NVD status is currently Received, meaning the record has not yet completed full NVD analysis.
Why It Matters
The CVSS v3.1 base score is 9.8 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
Every exploitability factor is at its worst case: the attack is reachable over the network, requires low complexity, needs no privileges, and requires no user interaction. That yields a maximum exploitability subscore of 3.9. Impact is high across confidentiality, integrity, and availability (5.9 impact subscore).
In practical terms, this is the profile of a bug that can be exploited remotely by anyone who can reach the application, with no credentials and no victim action required.
What's Vulnerable
- Vendor: Menulux Software Inc.
- Product: Mobile App
- Affected versions: all versions through 12.05.2026 (the vendor uses a date-style custom versioning scheme)
- Default status for other versions: unaffected
No CPE match strings have been published for this CVE yet, which will complicate automated inventory and scanner-based discovery. Identification will need to be done against vendor version data directly.
Patch Status
The supplied source material does not include a vendor patch, fixed version, or workaround. The only remediation guidance available is the USOM security advisory (TR-26-0729) linked below.
This CVE does not appear in the CISA Known Exploited Vulnerabilities catalog in the supplied data; there is no KEV entry, and therefore no confirmation of active exploitation and no KEV-mandated remediation due date at this time.
Sources
- NVD, CVE-2026-2346: https://nvd.nist.gov/vuln/detail/CVE-2026-2346
- USOM (Turkish national CERT) advisory TR-26-0729: https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0729