CVE-2026-19043: Authorization Bypass Critical POS Management Functions in Menulux Software's Menulux Portal
Published Sep 4, 2026
·Updated
Missing Authorization vulnerability in Menulux Software Inc. Menulux Portal allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects Menulux Portal: before 20260903211448.
Affected Software
1 affected component
Menulux Software Menulux Portal<20260903211448
Event History
Sep 4, 2026
CVE Published
via MITRE·11:49 AM
Data Sourced
via MITRE·11:49 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
Menulux Portal versions before 20260903211448 are affected.
2
What level of access does an attacker need?
The vulnerability requires low privileges. It can be exploited over the network without user interaction.
3
What is the potential impact?
A low-privileged user may access functionality that is not properly constrained by access-control lists. The reported impact is limited to confidentiality, with no reported integrity or availability impact.