CVE-2026-19051
—Plaintext Password Storage in Menulux Portal Exposes Embedded Credentials
Menulux Portal prior to build 20260903211448 stores a password in plaintext rather than using a hashed or encrypted format (CWE-256). An attacker who has obtained low-privileged access to the portal over the network can retrieve this embedded sensitive data without user interaction. Successful exploitation primarily yields disclosure of the stored password, which could enable further access if the credential is reused elsewhere; the flaw carries high confidentiality impact with limited integrity impact. Any organization running an affected version of Menulux Portal, the web management portal tied to the Menulux restaurant/POS management platform, is exposed. There are no known exploits, no public proof-of-concept, it is not in CISA's KEV catalog, and EPSS estimates only a 0.2% chance of exploitation in the next 30 days.
What to do: Upgrade Menulux Portal to version 20260903211448 or later. Because passwords may have been stored in plaintext, rotate any credentials managed by or stored in the portal after patching, and verify whether those credentials are reused on other systems. Restrict network access to the portal in the interim as a precaution.
| Menulux Software Inc. Menulux Portal | all versions before 20260903211448 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Plaintext storage of a password vulnerability in Menulux Software Inc. Menulux Portal allows Retrieve Embedded Sensitive Data. This issue affects Menulux Portal: before 20260903211448.
- Weakness
- CWE-256
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.