{"id":"CVE-2026-79348","title":"KitchenAsty through 0.3.0 contains a broken object level authorization (IDOR) vulnerability in the reservations API","summary":"KitchenAsty through 0.3.0 contains a broken object level authorization (IDOR) vulnerability in the reservations API. The endpoint GET /api/reservations/:id in packages/server applies the authenticate middleware but performs no ownership …","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-639"],"published":"2026-09-29","updated":"2026-09-30","sourceUpdated":"2026-09-30T17:32:07.107","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-79348","references":[{"url":"https://github.com/mighty840/kitchenasty","label":"cve@mitre.org"},{"url":"https://github.com/mighty840/kitchenasty/blob/main/packages/server/src/controllers/reservation.controller.ts","label":"cve@mitre.org"},{"url":"https://github.com/mighty840/kitchenasty/blob/main/packages/server/src/routes/reservation.routes.ts","label":"cve@mitre.org"},{"url":"https://github.com/mighty840/kitchenasty/pull/43","label":"cve@mitre.org"},{"url":"https://github.com/mighty840/kitchenasty/security/advisories/GHSA-2w4m-hjg2-2v92","label":"cve@mitre.org"}],"tags":["nvd","cve.org"],"epss":0.00217,"epssPercentile":0.10985,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-30T15:06:56.154674Z"},"ingestedAt":"2026-09-29T20:46:06.448Z","slug":"CVE-2026-79348","body":"## Overview\n\nKitchenAsty through 0.3.0 contains a broken object level authorization (IDOR) vulnerability in the reservations API. The endpoint GET /api/reservations/:id in packages/server applies the authenticate middleware but performs no ownership or role check, and the getReservation handler in packages/server/src/controllers/reservation.controller.ts returns the record retrieved by the client-supplied identifier without comparing reservation.customerId to the authenticated principal\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}