Authorization Bypass in Tandoor Recipes Affects User Privacy
CVE-2026-35045
8.1HIGH
What is CVE-2026-35045?
Tandoor Recipes, a platform for managing recipes, has a vulnerability in its recipe batch update feature. Prior to version 2.6.4, the PUT /api/recipe/batch_update/ endpoint allowed any authenticated user within a designated Space to modify any recipe, including those marked private by other users. This flaw bypasses necessary object-level authorization, potentially exposing private recipes to unauthorized users and enabling tampering with metadata. Users are advised to upgrade to version 2.6.4 to mitigate these risks.
Affected Version(s)
recipes < 2.6.4
