CVE-2026-41872
HIGHEpg, Inc. "Kura Sushi Official App" For Android - Improper Certificate Validation
Title source: ruleDescription
"Kura Sushi Official App" provided by EPG, Inc. is vulnerable to improper certificate validation. A man-in-the-middle attack may allow eavesdropping on, or altering, the communication on push notifications between the affected application and the relevant server.
References (3)
Core 3
Scores
CVSS v3
7.4
EPSS
0.0016
EPSS Percentile
5.5%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-295
Status
published
Products (2)
EPG, Inc./"Kura Sushi Official App" for Android
from 2.0.11 to 3.9.10
EPG, Inc./"Kura Sushi Official App" for iOS
from 2.0.11 to 3.9.10
Published
May 12, 2026
Tracked Since
May 12, 2026