CVE-2026-41872 Details
Description
"Kura Sushi Official App" provided by EPG, Inc. is vulnerable to improper certificate validation. A man-in-the-middle attack may allow eavesdropping on, or altering, the communication on push notifications between the affected application and the relevant server.
A vulnerability exists in the Kura Sushi Official App by EPG, Inc., due to improper validation of certificates. This flaw can lead to a man-in-the-middle attack, where an attacker could intercept or modify push notification communications between the app and its server. The vulnerability is present in the iOS version 2.0.11 prior to 3.9.10 and in the Android version 2.0.11 prior to 3.9.10.
Users are advised to update the Kura Sushi Official App to version 3.9.11, available on the App Store and Google Play.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 12, 2026CISA-ADP
Assessed May 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://apps.apple.com/jp/app/id942355925 | [email protected] | ProductVendor |
| https://jvn.jp/en/jp/JVN38632731/ | [email protected] | AdvisoryRemedy |
| https://play.google.com/store/apps/details?id=jp.co.kura_corpo&hl=ja | [email protected] | ProductVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-295 | Improper Certificate Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| EPG Kura Sushi Official App | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 12, 2026 | New CVE Received | [email protected] |
Volerion