CVE-2026-79348EPSS p8.9%
CVE-2026-79348CVE-2026-79348
Description
KitchenAsty through 0.3.0 contains a broken object level authorization (IDOR) vulnerability in the reservations API. The endpoint GET /api/reservations/:id in packages/server applies the authenticate middleware but performs no ownership or role check, and the getReservation handler in packages/server/src/controllers/reservation.controller.ts returns the record retrieved by the client-supplied identifier without comparing reservation.customerId to the authenticated principal
Scoring
| CVSS | 4.3 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
| EPSS | 0.20% probability of exploitation · percentile 8.9% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-30 |