SYS::ONLINE
Wasteland.
Briefs1680
Issues22
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-2346 2026-08-03

Menulux Mobile App Hit With Critical Authorization Bypass

"A critical-severity authorization bypass in Menulux Software Inc.'s Mobile App lets unauthenticated, remote attackers manipulate user-controlled keys to compromise software integrity, scoring a 9.8 CVSS."

A critical-severity authorization bypass in Menulux Software Inc.'s Mobile App lets unauthenticated, remote attackers manipulate user-controlled keys to compromise software integrity, scoring a 9.8 CVSS.

What Is It

CVE-2026-2346 is an authorization bypass through a user-controlled key (CWE-639) in Menulux Software Inc.'s Mobile App. The flaw allows a Software Integrity Attack; an attacker supplies or tampers with a key value that the application trusts for authorization decisions, bypassing the intended access controls.

The vulnerability was published on 2026-08-03 and reported by USOM (Turkey's national CERT, [email protected]). Its NVD status is currently Received, meaning the record has not yet completed full NVD analysis.

Why It Matters

The CVSS v3.1 base score is 9.8 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.

Every exploitability factor is at its worst case: the attack is reachable over the network, requires low complexity, needs no privileges, and requires no user interaction. That yields a maximum exploitability subscore of 3.9. Impact is high across confidentiality, integrity, and availability (5.9 impact subscore).

In practical terms, this is the profile of a bug that can be exploited remotely by anyone who can reach the application, with no credentials and no victim action required.

What's Vulnerable

No CPE match strings have been published for this CVE yet, which will complicate automated inventory and scanner-based discovery. Identification will need to be done against vendor version data directly.

Patch Status

The supplied source material does not include a vendor patch, fixed version, or workaround. The only remediation guidance available is the USOM security advisory (TR-26-0729) linked below.

This CVE does not appear in the CISA Known Exploited Vulnerabilities catalog in the supplied data; there is no KEV entry, and therefore no confirmation of active exploitation and no KEV-mandated remediation due date at this time.

Sources