CVE-2026-93736 Details
Description
Mealie before 3.21.0 fails to validate user ownership in the ratings and favorites endpoints, allowing authenticated attackers to read any user's recipe ratings and favorites by specifying arbitrary user IDs in the URL path. Attackers can access private recipe identifiers, rating values, and favorite flags belonging to other users across different groups or households.
A vulnerability in Mealie versions prior to 3.21.0 allows authenticated users to access other users' recipe ratings and favorites through the ratings and favorites endpoints. This is achieved by specifying arbitrary user IDs in the URL, bypassing ownership validation. The flaw enables access to private recipe identifiers, rating values, and favorite flags of users across different groups or households.
Users can be restricted to only access their own ratings and favorites. This can be done by modifying the endpoint to check that the user ID in the URL matches the ID of the authenticated user making the request.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 18, 2026CISA-ADP
Assessed Sep 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Mealie | >= 0, < 3.21.0 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 18, 2026 | CVE Modified | CISA-ADP |
| Sep 18, 2026 | New CVE Received | [email protected] |
Volerion