Junglewise Threat Intelligence

CVE-2026-19081: Gastromenum Ticket and QR Menu System missing authorization

CVE-2026-19081 · Severity: medium · CVSS 4.3 · Published 2026-09-04

Executive brief

Gastromenum Ticket and QR Menu System is a restaurant management platform for handling reservations and digital menus via QR codes. A missing authorization flaw allows users to access functionality that should be restricted by access control rules, potentially enabling unauthorized operations such as viewing or modifying reservation or menu data.

Technical details

This vulnerability is a missing authorization (access control bypass) issue in Gastromenum Ticket and QR Menu System affecting versions before 2026.08.31. The vulnerability allows an authenticated or potentially unauthenticated attacker to access functionality that should be restricted by access control lists (ACLs). The precise attack vector and preconditions are not fully detailed in the advisory, but the CVSS score of 4.3 suggests limited scope and impact. A patch is available in version 2026.08.31 and later.

Affected products

  • Gastromenum Ticket and QR Menu System before 2026.08.31

Timeline

  • 2026-09-04: disclosed
  • 2026-08-31: patched: Patch available in version 2026.08.31 and later

References

Related threats