---
cve: "CVE-2026-101033"
severity: "MEDIUM"
cvss: 5.3
epss: "0.2%"
vendor: "TomBursch"
kev: false
exploited: false
published: "2026-09-27 14:16:29"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-30T21:15:09+02:00"
---

# CVE-2026-101033

> 5.3 MEDIUM · 🧪 PoC

## Beschreibung

KitchenOwl through 0.7.10 fails to verify that category IDs belong to the caller's household in expense and item operations. Authenticated attackers can enumerate category IDs from other households to read their category names, budgets, and colors, breaking household isolation.

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |

## Patch verfügbar (OSV)

- 09aaf5fbd2343fcc10b12e906c63c3764dd38919 (Commit)
- c15f6cb21a98d5eb70746bee6b63773a6d6a6251 (Commit)

## Referenzen

- <https://github.com/TomBursch/kitchenowl/issues/1154>
- <https://github.com/TomBursch/kitchenowl/pull/1155>
- <https://github.com/TomBursch/kitchenowl/commit/c15f6cb21a98d5eb70746bee6b63773a6d6a6251>
- <https://github.com/TomBursch/kitchenowl/blob/09aaf5fbd2343fcc10b12e906c63c3764dd38919/backend/app/controller/expense/expense_controller.py#L115-L118>
- <https://github.com/TomBursch/kitchenowl/blob/09aaf5fbd2343fcc10b12e906c63c3764dd38919/backend/app/controller/item/item_controller.py#L86-L88>
- <https://github.com/TomBursch/kitchenowl>
- <https://www.vulncheck.com/advisories/kitchenowl-through-0.7.10-idor-via-unchecked-category-id>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-101033) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
