Privilege Escalation in Tandoor Recipes Application
CVE-2026-28503
5.5MEDIUM
What is CVE-2026-28503?
The Tandoor Recipes application, used for recipe management and meal planning, contains a vulnerability that permits an admin from one space to access and manage synchronization operations across different spaces. Specifically, the SyncViewSet.query_synced_folder() function in versions prior to 2.6.0 does not correctly filter Sync objects by space. This flaw enables potential unauthorized access to Sync configurations, including Dropbox and Nextcloud, and allows viewing of sync logs from other spaces. Version 2.6.0 addresses and patches this issue.
Affected Version(s)
recipes < 2.6.0
