CVE-2026-79348 Details
Description
KitchenAsty through 0.3.0 contains a broken object level authorization (IDOR) vulnerability in the reservations API. The endpoint GET /api/reservations/:id in packages/server applies the authenticate middleware but performs no ownership or role check, and the getReservation handler in packages/server/src/controllers/reservation.controller.ts returns the record retrieved by the client-supplied identifier without comparing reservation.customerId to the authenticated principal
A broken object-level authorization vulnerability has been identified in the KitchenAsty reservations API, specifically in versions through 0.3.0. The vulnerability exists in the GET /api/reservations/:id endpoint, which applies authentication but lacks proper ownership or role checks. As a result, any authenticated customer can access any reservation by providing its ID, exposing sensitive information such as the customer's name, email, phone number, private comments, and reservation details including date, time, party size, assigned table, and location.
Users can upgrade to KitchenAsty version 0.3.1, which fixes the vulnerability by enforcing ownership checks on the GET /api/reservations/:id endpoint. For those unable to upgrade immediately, it is possible to block or restrict this endpoint at the reverse proxy, although this may disrupt the storefront's ability to display a customer's own booking details.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| KitchenAsty | <= 0.3.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion