CVE-2026-41872

Severity CVSS v4.0:
CRITICAL
Type:
CWE-295 Improper Certificate Validation
Publication date:
12/05/2026
Last modified:
12/05/2026

Description

"Kura Sushi Official App" provided by EPG, Inc. is vulnerable to improper certificate validation. A man-in-the-middle attack may allow eavesdropping on, or altering, the communication on push notifications between the affected application and the relevant server.