CVE-2026-79348 | KitchenAsty up to 0.3.0 Reservations API reservation.controller.ts getReservation ID authorization
A vulnerability marked as problematic has been reported in KitchenAsty up to 0.3.0. Impacted is the function getReservation of the file packages/server/src/controllers/reservation.controller.ts of the component Reservations API. The manipulation of the argument ID leads to authorization bypass.
This vulnerability is traded as CVE-2026-79348. It is possible to initiate the attack remotely. There is no exploit available.VulDB Recent EntriesRead More