CVE-2026-19051: Plaintext Storage of User Credentials in Menulux Software's Menulux Portal
Published Sep 4, 2026
·Updated
Plaintext storage of a password vulnerability in Menulux Software Inc. Menulux Portal allows Retrieve Embedded Sensitive Data.
This issue affects Menulux Portal: before 20260903211448.
Affected Software
1 affected component
Menulux Software Menulux Portal<20260903211448
Event History
Sep 4, 2026
CVE Published
via MITRE·11:53 AM
Data Sourced
via MITRE·11:53 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The vulnerability has a low-privileges requirement. It can be exploited over the network without user interaction.
2
What is the likely impact if the issue is exploited?
An attacker may retrieve embedded sensitive data, including plaintext-stored passwords. The reported impact includes high confidentiality impact and low integrity impact, with no availability impact.
3
Which Menulux Portal releases are affected?
Menulux Portal versions before 20260903211448 are affected. The provided data does not identify a workaround or mitigation for installations that cannot yet update.