Junglewise Threat Intelligence

CVE-2026-10711: AKIN Software CafePlus missing authentication for critical function

CVE-2026-10711 · Severity: high · CVSS 8.8 · Published 2026-06-23

Vendors: AKINSOFT.

Executive brief

AKIN Software CafePlus, a management system used for internet cafes and similar businesses, contains a security flaw that allows unauthorized access to sensitive administrative functions. An attacker on the same local network could bypass security controls to gain full control over the system, potentially leading to data theft or service disruption. This could allow an unauthorized user to manipulate billing, access customer data, or shut down operations.

Technical details

A missing authentication vulnerability (CWE-306) exists in AKIN Software CafePlus versions 12.05.03 through 12.05.04. The flaw allows an attacker with adjacent network access to execute critical functions that are not properly constrained by Access Control Lists (ACLs). Because no authentication is required for these sensitive operations, an unauthenticated attacker can achieve full compromise of confidentiality, integrity, and availability. The issue is addressed in version 12.05.04.

Affected products

  • AKIN Software Computer Import Export Industry and Trade Ltd. CafePlus 12.05.03 to 12.05.04

Timeline

  • 2026-06-23: disclosed
  • 2026-06-23: advisory

References