Junglewise Threat Intelligence

CVE-2025-13479: PosCube QR Menu authorization bypass via user-controlled key

CVE-2025-13479 · Severity: high · CVSS 7.5 · Published 2026-05-21

Technologies: PosCube Hardware Software and Consulting Ltd. QR Menu. Vendors: PosCube Hardware Software and Consulting Ltd..

Executive brief

PosCube QR Menu, a digital menu system used by restaurants and hospitality businesses, contains a security flaw that allows unauthorized access to sensitive information. By manipulating specific identifiers in the system, an attacker can bypass security checks to view data they should not be able to see. This could lead to the exposure of customer or business information, and the vendor has not yet responded to reports of this issue.

Technical details

An authorization bypass vulnerability (CWE-639) exists in PosCube QR Menu through version 21052026. The flaw stems from an Insecure Direct Object Reference (IDOR) where the application relies on user-controlled keys or identifiers to grant access to resources without performing adequate server-side authorization checks. A remote, unauthenticated attacker can exploit this by modifying these identifiers in network requests to access data belonging to other users or the system. As of the disclosure date, the vendor has not provided a patch or response.

Affected products

  • PosCube Hardware Software and Consulting Ltd. QR Menu through 21052026

Timeline

  • 2026-05-21: advisory: NVD published the vulnerability record.
  • 2026-05-21: disclosed: Public disclosure by the Computer Emergency Response Team of the Republic of Turkey.

References