Junglewise Threat Intelligence

CVE-2026-6853: Başbelen Group Pause+ Mobile App authentication bypass

CVE-2026-6853 · Severity: critical · CVSS 9.8 · Published 2026-06-12

Executive brief

The Pause+ mobile application, used by food and cafe businesses for operations, contains a security flaw that fails to limit login attempts. This allows an attacker to repeatedly guess passwords until they gain unauthorized access to user accounts. Successful exploitation could lead to the theft of customer data, financial information, or complete takeover of business accounts.

Technical details

A vulnerability classified as CWE-307 (Improper Restriction of Excessive Authentication Attempts) exists in the Pause+ Mobile App. The application fails to implement rate limiting or account lockout mechanisms on its authentication interface. A remote, unauthenticated attacker can perform brute-force or credential stuffing attacks over the network to bypass authentication. This allows for full unauthorized access to the application's data and functionality. The issue is confirmed to affect versions 1.0.6 through 1.5.

Affected products

  • Başbelen Group Food Cafe Businesses Industry and Trade Ltd. Co. Pause+ Mobile App v1.0.6 to v1.5

Timeline

  • 2026-06-12: disclosed
  • 2026-06-12: advisory

References