CVE-2026-1600Disclosure(bdtask / bhojon)

LOWCVSS 2.1 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was identified in Bdtask Bhojon All-In-One Restaurant Management System up to 20260116. The impacted element is an unknown function of the file /hungry/addtocart of the component Add-to-Cart Submission Endpoint. The manipulation of the argument price/allprice leads to business logic errors. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-840

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bhojon

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-01-29); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
bhojon

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-01-29: 2Mentions · 2026-06-13: 1Technical Details · 2026-01-29: 1Technical Details · 2026-06-13: 101-2906-13
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-01-292
Disclosure1General1
2026-06-131
Disclosure1
Full discourse3 posts
  • Dark Web Informer@DarkWebInformer
    Disclosure

    CVE-2026-1600: The backend accepts user-controlled pricing values without validating them against server-side product data. An attacker could modify the price field in the POST request, causing the server to process a fraudulent or reduced price. Video Credit: http://youtube.com/@4m3rr0r // X: @4m3rr0r

    Post summary

    The post presents a new vulnerability (CVE‑2026‑1600) that allows attackers to manipulate pricing data via POST requests due to missing server‑side validation.

    491582910.7K
    224.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-1600 Bdtask Bhojon Restaurant Management System Remote Business Logic Vulnerab... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1600 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    A brief notification of CVE-2026-1600 with links to external vulnerability details, but no substantive information is provided.

    0000056
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1600 A vulnerability was identified in Bdtask Bhojon All-In-One Restaurant Management System up to 20260116. The impacted element is an unknown function of the file /hungry/… https://www.cve.org/CVERecord?id=CVE-2026-1600

    Post summary

    A new CVE‑2026‑1600 vulnerability was identified in Bdtask Bhojon All‑In‑One Restaurant Management System, affecting an unspecified function in the /hungry/ file; no PoC, exploit, or patch information is provided.

    00000137
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbdtaskbhojon---

Explore more