CVE-2026-41872
Published: May 12, 2026
Modified: May 12, 2026
CVSS v3.0
7.4
Description
"Kura Sushi Official App" provided by EPG, Inc. is vulnerable to improper certificate validation. A man-in-the-middle attack may allow eavesdropping on, or altering, the communication on push notifications between the affected application and the relevant server.
| Vendor | Product | Versions |
|---|---|---|
EPG, Inc. | "Kura Sushi Official App" for Android | affected from 2.0.11 to 3.9.10 |
EPG, Inc. | "Kura Sushi Official App" for iOS | affected from 2.0.11 to 3.9.10 |
Weaknesses (CWE)
CVSS v3.0 Details
CVSS v3.0 Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now