CVE-2026-93736: Mealie before 3.21.0 Information Disclosure via Ratings Endpoint

Published Sep 18, 2026
·
Updated

Mealie before 3.21.0 fails to validate user ownership in the ratings and favorites endpoints, allowing authenticated attackers to read any user's recipe ratings and favorites by specifying arbitrary user IDs in the URL path. Attackers can access private recipe identifiers, rating values, and favorite flags belonging to other users across different groups or households.

Affected Software

1 affected component
Mealie Mealie<3.21.0

Event History

Sep 18, 2026
CVE Published
via MITRE·04:04 PM
Data Sourced
via MITRE·04:04 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any authenticated Mealie user can exploit it by supplying another user's ID in the ratings or favorites endpoint URL path. The issue can expose data across different groups or households.

2

What information could be disclosed?

An attacker can read other users' recipe ratings, favorite flags, and private recipe identifiers.

3

Which versions are affected?

Mealie versions before 3.21.0 are affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203