CVE-2026-79348: Medium severity KitchenAsty vulnerability

Published Sep 29, 2026
·
Updated

KitchenAsty through 0.3.0 contains a broken object level authorization (IDOR) vulnerability in the reservations API. The endpoint GET /api/reservations/:id in packages/server applies the authenticate middleware but performs no ownership or role check, and the getReservation handler in packages/server/src/controllers/reservation.controller.ts returns the record retrieved by the client-supplied identifier without comparing reservation.customerId to the authenticated principal

Affected Software

1 affected component
KitchenAsty<=0.3.0

Event History

Sep 29, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Data Sourced
via NVD·08:17 PM
DescriptionSeverity

Frequently Asked Questions

1

Who can exploit this issue?

Any authenticated user with a valid account can exploit it. The endpoint requires authentication, but it does not verify that the requester owns the reservation or has an authorized role.

2

What does an attacker need to access another reservation?

The attacker needs to send a request to GET /api/reservations/:id using a reservation identifier for a record they do not own. Network access to the API and low-privileged authenticated access are required.

3

What information can be exposed?

The affected handler returns the reservation record selected by the client-supplied identifier. The provided data does not specify the exact fields contained in reservation records.

4

Are deployments affected by default?

Deployments running KitchenAsty through version 0.3.0 are affected where the described reservations endpoint is available. Authentication alone does not prevent the issue because the route lacks ownership and role authorization checks.

5

What can be done if an update is not immediately available?

Restrict access to the reservations API to trusted users and apply an authorization check that compares the authenticated principal with reservation.customerId, while allowing any intended privileged roles explicitly. Monitor requests to the endpoint for users retrieving reservation IDs that do not belong to them.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203