CVE-2025-14317: Emaintenance Crazy Bubble Tea

High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.

In Crazy Bubble Tea mobile application authenticated attacker can obtain personal information about other users by enumerating a `loyaltyGuestId` parameter. Server does not verify the permissions required to obtain the data. This issue was fixed in version 915 (Android) and 7.4.1 (iOS).

Affected products

  • Emaintenance Crazy Bubble Tea: before 915 (fixed in 915); before 7.4.1 (fixed in 7.4.1)

Published 2026-01-14. Last modified 2026-06-17.