CVE-2026-101033 - KitchenOwl through 0.7.10 IDOR via unchecked category ID
CVE ID :CVE-2026-101033
Published : Sept. 27, 2026, 2:16 p.m. | 2 hours, 55 minutes ago
Description :KitchenOwl through 0.7.10 fails to verify that category IDs belong to the caller's household in expense and item operations. Authenticated attackers can enumerate category IDs from other households to read their category names, budgets, and colors, breaking household isolation.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 27, 2026, 2:16 p.m. | 2 hours, 55 minutes ago
Description :KitchenOwl through 0.7.10 fails to verify that category IDs belong to the caller's household in expense and item operations. Authenticated attackers can enumerate category IDs from other households to read their category names, budgets, and colors, breaking household isolation.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...