Impact
KitchenOwl up to version 0.7.10 lacks validation that category identifiers belong to the caller’s household during expense and item operations. Attackers who have authenticated access to the system can enumerate category IDs owned by other households and subsequently retrieve sensitive information such as category names, associated budgets, and visual themes. This weakness undermines household isolation but does not grant broader system or network compromise.
Affected Systems
The affected product is KitchenOwl from TomBursch. All installations running releases through 0.7.10 are vulnerable. Specific version details are limited to the 0.7.10 release and earlier; newer releases are presumed to contain the fix.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate risk. No EPSS data is available, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is only viable for users who have already authenticated to the application, making it an intra-application privilege‑escalation scenario. Successful exploitation would allow a user to read data belonging to other households, violating confidentiality and isolation guarantees. Given the lack of network‑level exposure, external attackers cannot launch the attack without first gaining user credentials.
OpenCVE Enrichment