Junglewise Threat Intelligence

CVE-2026-19043: Menulux Portal missing authorization in access control

CVE-2026-19043 · Severity: medium · CVSS 4.3 · Published 2026-09-04

Technologies: Menulux Software Inc. Menulux Portal. Vendors: Menulux Software Inc..

Executive brief

Menulux Portal, a web application platform, fails to properly enforce access control rules in certain areas of the application. An attacker could bypass authorization checks to access functionality or data they should not have permission to use, potentially leading to unauthorized data access or actions.

Technical details

This vulnerability is a missing authorization (CWE-863) issue where access control lists (ACLs) fail to properly constrain access to certain functionality in Menulux Portal. The vulnerability allows attackers to access features and operations that should be restricted based on user role or permissions. The attack vector appears to be network-based and likely does not require authentication, though the exact attack preconditions are not detailed in available references. Successful exploitation could result in unauthorized access to sensitive functionality or data. The issue affects versions before 20260903211448, and a patch is available in that version or later.

Affected products

  • Menulux Software Inc. Menulux Portal before 20260903211448

Timeline

  • 2026-09-04: disclosed
  • 2026-09-03: patched

References

Related threats