Retour à la veille

CVE-2026-101033

Publié : 27 septembre 2026
Modifié : 27 septembre 2026
Lien officiel NVD
Score CVSS
4.3
MEDIUM

Description détaillée

KitchenOwl through 0.7.10 fails to verify that category IDs belong to the caller's household in expense and item operations. Authenticated attackers can enumerate category IDs from other households to read their category names, budgets, and colors, breaking household isolation.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Références et Patchs