ZeroHour

CVE-2026-19080

niche

Response-Discrepancy Account Footprinting in Menulux Portal

CVSS 3.1
7.5 high
EPSS
<1%p23
Published
()
Modified
AI analysis

Menulux Portal versions before build 20260903211448 exhibit an observable response discrepancy (CWE-204): the application responds differently depending on whether a requested or submitted account exists, allowing unauthenticated remote attackers to perform account footprinting. An attacker triggers the flaw by sending authentication- or account-related requests over the network and comparing the responses (e.g., differing messages, codes, or timing) to determine valid accounts. The attacker gains confirmation of existing usernames/accounts, which is a confidentiality-only impact (CVSS C:H, I:N, A:N) but provides reconnaissance that can feed follow-on password spraying or brute-force attempts. Affected parties are any organization running an affected Menulux Portal instance reachable over a network. Exploitation is not currently known: there is no public PoC, the issue is not in CISA KEV, and EPSS puts 30-day exploitation probability at roughly 0.3%.

What to do: Upgrade Menulux Portal to build 20260903211448 or later. Where immediate upgrade is not possible, normalize authentication and account-recovery responses (identical generic messages, similar timing) and apply rate limiting on login/account endpoints to blunt enumeration. Check portal access logs for patterns consistent with account enumeration or follow-on login attempts against discovered accounts.

Affected
Menulux Software Inc. Menulux Portalbefore 20260903211448
Estimated exposure
nichelikely hundreds to low thousands of restaurant portal deployments (niche vendor; no public install counts) — Menulux is a small restaurant-management/POS vendor serving small and mid-sized restaurants and no public install, user, or internet-exposure counts are available, so this is an order-of-magnitude estimate based on the vendor's market…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Observable response discrepancy vulnerability in Menulux Software Inc. Menulux Portal allows Account Footprinting. This issue affects Menulux Portal: before 20260903211448.

Weakness
CWE-204
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.