Vulnerability Description
"Kura Sushi Official App" provided by EPG, Inc. is vulnerable to improper certificate validation. A man-in-the-middle attack may allow eavesdropping on, or altering, the communication on push notifications between the affected application and the relevant server.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://apps.apple.com/jp/app/id942355925
- https://jvn.jp/en/jp/JVN38632731/
- https://play.google.com/store/apps/details?id=jp.co.kura_corpo&hl=ja
FAQ
What is CVE-2026-41872?
CVE-2026-41872 is a vulnerability with a CVSS score of 7.4 (HIGH). "Kura Sushi Official App" provided by EPG, Inc. is vulnerable to improper certificate validation. A man-in-the-middle attack may allow eavesdropping on, or altering, the communication on push notifica...
How severe is CVE-2026-41872?
CVE-2026-41872 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-41872?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.