Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Net208B

#55780of 57,469
4.3Total CVSS
Vulnerabilities · 1
PT-2026-102910
4.3
2026-09-29
Unknown · Kitchenasty · CVE-2026-79348
**Name of the Vulnerable Software and Affected Versions** KitchenAsty versions prior to 0.3.1 **Description** Broken object level authorization (IDOR) exists in the reservations API. The endpoint 'GET /api/reservations/:id' in packages/server uses authentication middleware but fails to perform ownership or role checks. Consequently, the `getReservation()` handler in packages/server/src/controllers/reservation.controller.ts returns records based on the client-supplied `:id` without verifying if the `customerId` of the reservation matches the authenticated user. **Recommendations** Update KitchenAsty to a version newer than 0.3.0. As a temporary mitigation, restrict access to the 'GET /api/reservations/:id' endpoint.