CVE-2026-79348: n/a
KitchenAsty through 0.3.0 contains a broken object level authorization (IDOR) vulnerability in the reservations API. The endpoint GET /api/reservations/:id in packages/server applies the authenticate middleware but performs no ownership or role check, and the getReservation handler in packages/server/src/controllers/reservation.controller.ts returns the record retrieved by the client-supplied identifier without comparing reservation.customerId to the authenticated principal
AI Analysis
Technical Summary
CVE-2026-79348 describes an IDOR vulnerability in KitchenAsty through version 0.3.0. The vulnerability exists in the reservations API endpoint GET /api/reservations/:id, which applies authentication middleware but lacks authorization checks to confirm that the authenticated principal owns the requested reservation. Specifically, the getReservation handler returns reservation data based solely on the client-supplied identifier without verifying that reservation.customerId matches the authenticated user. This flaw permits unauthorized read access to reservation records of other users.
Potential Impact
An attacker with valid authentication and limited privileges can access reservation data of other users without authorization. The impact is limited to information disclosure (confidentiality loss) as the vulnerability does not allow modification or deletion of data. The CVSS 3.1 base score is 4.3, indicating a medium severity due to low complexity and no user interaction required.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should consider restricting access to the affected API endpoint or implementing additional authorization checks to ensure that the authenticated user can only access their own reservation records.
CVE-2026-79348: n/a
Description
KitchenAsty through 0.3.0 contains a broken object level authorization (IDOR) vulnerability in the reservations API. The endpoint GET /api/reservations/:id in packages/server applies the authenticate middleware but performs no ownership or role check, and the getReservation handler in packages/server/src/controllers/reservation.controller.ts returns the record retrieved by the client-supplied identifier without comparing reservation.customerId to the authenticated principal
CVSS v3.1
Score 4.3medium
Affected software
pkg:github/mighty840/kitchenastyRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-79348 describes an IDOR vulnerability in KitchenAsty through version 0.3.0. The vulnerability exists in the reservations API endpoint GET /api/reservations/:id, which applies authentication middleware but lacks authorization checks to confirm that the authenticated principal owns the requested reservation. Specifically, the getReservation handler returns reservation data based solely on the client-supplied identifier without verifying that reservation.customerId matches the authenticated user. This flaw permits unauthorized read access to reservation records of other users.
Potential Impact
An attacker with valid authentication and limited privileges can access reservation data of other users without authorization. The impact is limited to information disclosure (confidentiality loss) as the vulnerability does not allow modification or deletion of data. The CVSS 3.1 base score is 4.3, indicating a medium severity due to low complexity and no user interaction required.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should consider restricting access to the affected API endpoint or implementing additional authorization checks to ensure that the authenticated user can only access their own reservation records.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2026-08-25T00:00:00.000Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6abc1a64680226ef6837aa75
Added to database: 09/29/2026, 20:07:00 UTC
Last enriched: 09/29/2026, 20:21:27 UTC
Last updated: 09/30/2026, 03:38:32 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.