CVE-2026-19081: Missing Authorization Allows Unauthorized Access to Critical POS Functions in Gastromenum's Gastromenum Ticket and QR Menu System
Published Sep 4, 2026
·Updated
Missing Authorization vulnerability in Gastromenum Gastromenum Ticket and QR Menu System allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects Gastromenum Ticket and QR Menu System: before 2026.08.31.
Affected Software
1 affected component
Gastromenum Ticket and QR Menu System<2026.08.31
Event History
Sep 4, 2026
CVE Published
via MITRE·01:57 PM
Data Sourced
via MITRE·01:57 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
Gastromenum Ticket and QR Menu System versions before 2026.08.31 are affected.
2
What level of access does an attacker need?
The vulnerability requires low privileges. It can be exploited remotely without user interaction.
3
What is the expected impact?
An attacker may access functionality that is not properly restricted by access-control lists. The reported impact is limited to confidentiality; integrity and availability impacts are not indicated.