CVE-2026-41872Patch

LOWCVSS 9.1 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

"Kura Sushi Official App" provided by EPG, Inc. is vulnerable to improper certificate validation. A man-in-the-middle attack may allow eavesdropping on, or altering, the communication on push notifications between the affected application and the relevant server.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-05-11); latest day: 2
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-05-11: 2Mentions · 2026-05-12: 1Mentions · 2026-05-13: 2Patch / Workaround · 2026-05-11: 1Patch / Workaround · 2026-05-12: 1Technical Details · 2026-05-11: 2Technical Details · 2026-05-12: 1Technical Details · 2026-05-13: 205-1105-1205-13
Signal classification3 categories
Patch
240.0%
General
240.0%
Disclosure
120.0%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-05-112
Disclosure1Patch1
2026-05-121
Patch1
2026-05-132
General2
Full discourse5 posts
  • Takamichi Saito, 齋藤孝道@saitolab_org
    Disclosure

    「プッシュ通知に関する通信における証明書検証不備(CVE-2026-41872)」/ くら寿司アプリに脆弱性 通信内容が盗聴・改ざんされる恐れ https://weekly.ascii.jp/elem/000/004/400/4400863/ @weeklyasciiより

    Post summary

    The article announces the discovery of a certificate verification flaw affecting push notifications in the KuraKura sushi app, highlighting potential interception or tampering of communications.

    04131479
    4.1K followersView on X
  • ボス@サイバーセキュリティの専門家@boss_sec_labo
    General

    https://security.splash-eng.com/higashiyama-qilin-ransomware-leak-2026/ https://security.splash-eng.com/kura-sushi-app-cve-2026-41872/ https://security.splash-eng.com/canon-multifunction-cve-2026-1789/ https://security.splash-eng.com/shinnihon-kentei-ransomware-2026/

    Post summary

    The linked articles appear to discuss newly disclosed CVEs and ransomware incidents, but they do not provide evidence of a PoC, exploit code, active exploitation, or a patch, though technical details about the vulnerabilities are likely present.

    0002061
    1.2K followersView on X
  • セキュリティ対策Lab@securityLab_jp
    General

    くら寿司 公式アプリに危険度の高い脆弱性 CVE-2026-41872-悪意ある無線LANでプッシュ通知の盗聴・改ざんが可能 https://rocket-boys.co.jp/security-measures-lab/kura-sushi-app-high-severity-flaw-cve-2026-41872/ #セキュリティ対策Lab #security #securitynews

    Post summary

    The post announces a high‑severity vulnerability (CVE‑2026‑41872) in the Kura Sushi app that permits malicious wireless LANs to eavesdrop and alter push notifications, but it provides no PoC, exploitation details, or patch information.

    01000196
    405 followersView on X
  • Entity@0x2ed3bb60
    Patch

    🚨 CVE-2026-41872: Kura Sushi Official App vulnerable to MITM. Certificate validation failure enables push notification interception. Entity detects EPG Inc deployment. Update immediately. https://0x2ed3bb60.xyz/threat/06018232187776cf

    Post summary

    The tweet announces CVE‑2026‑41872 against the Kura Sushi Official App, describing a certificate validation flaw that enables MITM push‑notification interception, and urges users to update immediately.

    0000029
    7 followersView on X
  • Autumn Good@autumn_good_35
    Patch

    『なお、開発者によると、本件の影響を受けるバージョンを使用している場合、起動時に即時アップデートを強制されるとのことです』 CVE-2026-41872 JVN#38632731: スマートフォンアプリ「くら寿司 公式アプリ」における証明書検証不備の脆弱性 https://jvn.jp/jp/JVN38632731/index.html

    Post summary

    The Japanese vendor will enforce an immediate update on affected versions of the Kurazushi app to address a certificate verification flaw (CVE‑2026‑41872).

    00000479
    6.8K followersView on X

Explore more