Unknown · Kitchenasty · CVE-2026-79348
**Name of the Vulnerable Software and Affected Versions**
KitchenAsty versions prior to 0.3.1
**Description**
Broken object level authorization (IDOR) exists in the reservations API. The endpoint 'GET /api/reservations/:id' in packages/server uses authentication middleware but fails to perform ownership or role checks. Consequently, the `getReservation()` handler in packages/server/src/controllers/reservation.controller.ts returns records based on the client-supplied `:id` without verifying if the `customerId` of the reservation matches the authenticated user.
**Recommendations**
Update KitchenAsty to a version newer than 0.3.0.
As a temporary mitigation, restrict access to the 'GET /api/reservations/:id' endpoint.