CVE-2026-19080
nicheResponse-Discrepancy Account Footprinting in Menulux Portal
Menulux Portal versions before build 20260903211448 exhibit an observable response discrepancy (CWE-204): the application responds differently depending on whether a requested or submitted account exists, allowing unauthenticated remote attackers to perform account footprinting. An attacker triggers the flaw by sending authentication- or account-related requests over the network and comparing the responses (e.g., differing messages, codes, or timing) to determine valid accounts. The attacker gains confirmation of existing usernames/accounts, which is a confidentiality-only impact (CVSS C:H, I:N, A:N) but provides reconnaissance that can feed follow-on password spraying or brute-force attempts. Affected parties are any organization running an affected Menulux Portal instance reachable over a network. Exploitation is not currently known: there is no public PoC, the issue is not in CISA KEV, and EPSS puts 30-day exploitation probability at roughly 0.3%.
What to do: Upgrade Menulux Portal to build 20260903211448 or later. Where immediate upgrade is not possible, normalize authentication and account-recovery responses (identical generic messages, similar timing) and apply rate limiting on login/account endpoints to blunt enumeration. Check portal access logs for patterns consistent with account enumeration or follow-on login attempts against discovered accounts.
| Menulux Software Inc. Menulux Portal | before 20260903211448 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Observable response discrepancy vulnerability in Menulux Software Inc. Menulux Portal allows Account Footprinting. This issue affects Menulux Portal: before 20260903211448.
- Weakness
- CWE-204
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.