CVE-2026-19080: Username Enumeration in Menulux Software's Menulux Portal
Published Sep 4, 2026
·Updated
Observable response discrepancy vulnerability in Menulux Software Inc. Menulux Portal allows Account Footprinting.
This issue affects Menulux Portal: before 20260903211448.
Affected Software
1 affected component
Menulux Portal<20260903211448
Event History
Sep 4, 2026
CVE Published
via MITRE·11:56 AM
Data Sourced
via MITRE·11:56 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
Menulux Portal deployments with versions before 20260903211448 are affected.
2
Can this be exploited remotely without an account or user interaction?
Yes. The supplied vector indicates network access, low attack complexity, no privileges required, and no user interaction required.
3
What could an attacker learn or do?
An attacker can use observable response differences to identify valid usernames or accounts. The provided impact information indicates high confidentiality impact, with no integrity or availability impact stated.