ZeroHour

CVE-2026-19051

Plaintext Password Storage in Menulux Portal Exposes Embedded Credentials

CVSS 3.1
7.1 high
EPSS
<1%p11
Published
()
Modified
AI analysis

Menulux Portal prior to build 20260903211448 stores a password in plaintext rather than using a hashed or encrypted format (CWE-256). An attacker who has obtained low-privileged access to the portal over the network can retrieve this embedded sensitive data without user interaction. Successful exploitation primarily yields disclosure of the stored password, which could enable further access if the credential is reused elsewhere; the flaw carries high confidentiality impact with limited integrity impact. Any organization running an affected version of Menulux Portal, the web management portal tied to the Menulux restaurant/POS management platform, is exposed. There are no known exploits, no public proof-of-concept, it is not in CISA's KEV catalog, and EPSS estimates only a 0.2% chance of exploitation in the next 30 days.

What to do: Upgrade Menulux Portal to version 20260903211448 or later. Because passwords may have been stored in plaintext, rotate any credentials managed by or stored in the portal after patching, and verify whether those credentials are reused on other systems. Restrict network access to the portal in the interim as a precaution.

Affected
Menulux Software Inc. Menulux Portalall versions before 20260903211448
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Plaintext storage of a password vulnerability in Menulux Software Inc. Menulux Portal allows Retrieve Embedded Sensitive Data. This issue affects Menulux Portal: before 20260903211448.

Weakness
CWE-256
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.