Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 30 Mar 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tandoor
Tandoor recipes |
|
| CPEs | cpe:2.3:a:tandoor:recipes:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Tandoor
Tandoor recipes |
|
| Metrics |
cvssV3_1
|
Fri, 27 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 27 Mar 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tandoorrecipes
Tandoorrecipes recipes |
|
| Vendors & Products |
Tandoorrecipes
Tandoorrecipes recipes |
Thu, 26 Mar 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, the `SyncViewSet.query_synced_folder()` action in `cookbook/views/api.py` (line 903) fetches a Sync object using `get_object_or_404(Sync, pk=pk)` without including `space=request.space` in the filter. This allows an admin user in Space A to trigger sync operations (Dropbox/Nextcloud/Local import) on Sync configurations belonging to Space B, and view the resulting sync logs. Version 2.6.0 patches the issue. | |
| Title | Tandoor Recipes has Cross-Space IDOR in SyncViewSet.query_synced_folder: missing space scoping on get_object_or_404 | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-27T13:58:12.010Z
Reserved: 2026-02-27T20:57:47.709Z
Link: CVE-2026-28503
Updated: 2026-03-27T13:47:47.383Z
Status : Analyzed
Published: 2026-03-26T19:16:57.113
Modified: 2026-03-30T19:28:48.307
Link: CVE-2026-28503
No data.
OpenCVE Enrichment
Updated: 2026-03-30T20:57:39Z