PT-2026-95483 · Mealie · Mealie

·

CVE-2026-93736

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Mealie versions prior to 3.21.0
Description Authenticated attackers can access private recipe identifiers, rating values, and favorite flags of other users across different groups or households. This occurs because the application fails to validate user ownership in the ratings and favorites endpoints when arbitrary user IDs are specified in the URL path.
Recommendations Update to version 3.21.0 or later.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93736

Affected Products

Mealie