CVE-2026-101033 | KitchenOwl through 0.7.10 fails to verify that category IDs belong to the caller's household in expense and item operations. Authenticated attackers can enumerate category IDs from other households to read their category names, budgets, and colors, breaking household isolation.
KitchenOwl through 0.7.10 fails to verify that category IDs belong to the caller's household in expense and item operations. Authenticated attackers can enumerate category IDs from other households to read their category names, budgets, and colors, breaking household isolation.
- 🔗 github.com/TomBursch/kitchenowl/issues/1154
- 🔗 github.com/TomBursch/kitchenowl/pull/1155
- 🔗 github.com/TomBursch/kitchenowl/commit/c15f6cb21a98d…
- 🔗 github.com/TomBursch/kitchenowl/blob/09aaf5fbd2343fc…
- 🔗 github.com/TomBursch/kitchenowl/blob/09aaf5fbd2343fc…
- 🔗 github.com/TomBursch/kitchenowl
- 🔗 www.vulncheck.com/advisories/kitchenowl-through-0.7.10-idor…
```Code``` unterstützt. Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-09-15 | 2026-09-28 |
|---|---|---|
| ≥90 % | 0 | 299 |
| ≥50 % | 0 | 958 |
| ≥10 % | 0 | 3 |
| <10 % | 300 | 250 |
CVE-2026-101033 | KitchenOwl through 0.7.10 fails to verify that category IDs belong to the caller's household in expense and item operations. Authenticated attackers can enumerate category IDs from other households to read their category names, budgets, and colors, breaking household isolation.
KitchenOwl through 0.7.10 fails to verify that category IDs belong to the caller's household in expense and item operations. Authenticated attackers can enumerate category IDs from other households to read their category names, budgets, and
Noch keine Analyse zu CVE-2026-101033
Sei der Erste: Einschätzung, Betroffenheit, Workaround oder PoC — mit Antworten im Thread.