Junglewise Threat Intelligence

CVE-2026-41872: EPG Inc. Kura Sushi Official App improper certificate validation

CVE-2026-41872 · Severity: high · CVSS 7.4 · Published 2026-05-12

Executive brief

The Kura Sushi Official App, used for restaurant reservations and ordering, fails to properly verify security certificates for push notifications. This flaw allows an attacker on the same network (such as a public Wi-Fi hotspot) to intercept or modify communications between the app and its servers. This could lead to the exposure of user information or the delivery of fraudulent notification content.

Technical details

The Kura Sushi Official App (Android and iOS) contains a CWE-295 (Improper Certificate Validation) vulnerability specifically affecting push notification communications. The application fails to adequately validate the TLS certificate presented by the server, enabling a man-in-the-middle (MitM) attack. An attacker positioned on the network path—most likely via a malicious or compromised wireless access point—can eavesdrop on or alter the data exchanged between the app and the notification server. The vulnerability was addressed in version 3.9.11 for both platforms.

Affected products

  • EPG, Inc. Kura Sushi Official App 2.0.11 to 3.9.10

Timeline

  • 2026-05-11: advisory: Initial advisory published by JVN/JPCERT
  • 2026-05-12: disclosed: CVE published to NVD
  • 2026-03-31: patched: Version 3.9.11 released to app stores

References