PT-2026-102910 · Unknown · Kitchenasty

·

CVE-2026-79348

·

Published

2026-09-29

·

Updated

2026-09-29

CVSS v3.1

4.3

Medium

VectorAC:L/AV:N/A:N/C:L/I:N/PR:L/S:U/UI:N
Name of the Vulnerable Software and Affected Versions KitchenAsty versions prior to 0.3.1
Description Broken object level authorization (IDOR) exists in the reservations API. The endpoint 'GET /api/reservations/:id' in packages/server uses authentication middleware but fails to perform ownership or role checks. Consequently, the getReservation() handler in packages/server/src/controllers/reservation.controller.ts returns records based on the client-supplied :id without verifying if the customerId of the reservation matches the authenticated user.
Recommendations Update KitchenAsty to a version newer than 0.3.0. As a temporary mitigation, restrict access to the 'GET /api/reservations/:id' endpoint.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-79348
GHSA-2W4M-HJG2-2V92

Affected Products

Kitchenasty