SEPTEMBER 25, 2026
Live Feed
Back to database
Case File

CVE-2026-41872

HIGH · CVSS 7.4 EPSS 0.16%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-05-12 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.4. See the original NVD description below for full technical details.

CVE
CVE-2026-41872
Severity
HIGH
CVSS
7.4
EPSS
0.16%

Original NVD Description

"Kura Sushi Official App" provided by EPG, Inc. is vulnerable to improper certificate validation. A man-in-the-middle attack may allow eavesdropping on, or altering, the communication on push notifications between the affected application and the relevant server.