CVE-2026-93736: Mealie before 3.21.0 Information Disclosure via Ratings Endpoint
Published Sep 18, 2026
·Updated
Mealie before 3.21.0 fails to validate user ownership in the ratings and favorites endpoints, allowing authenticated attackers to read any user's recipe ratings and favorites by specifying arbitrary user IDs in the URL path. Attackers can access private recipe identifiers, rating values, and favorite flags belonging to other users across different groups or households.
Affected Software
1 affected component
Mealie Mealie<3.21.0
Event History
Sep 18, 2026
CVE Published
via MITRE·04:04 PM
Data Sourced
via MITRE·04:04 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Any authenticated Mealie user can exploit it by supplying another user's ID in the ratings or favorites endpoint URL path. The issue can expose data across different groups or households.
2
What information could be disclosed?
An attacker can read other users' recipe ratings, favorite flags, and private recipe identifiers.
3
Which versions are affected?
Mealie versions before 3.21.0 are affected.