Description
Mealie before 3.21.0 fails to validate user ownership in the ratings and favorites endpoints, allowing authenticated attackers to read any user's recipe ratings and favorites by specifying arbitrary user IDs in the URL path. Attackers can access private recipe identifiers, rating values, and favorite flags belonging to other users across different groups or households.
Published: 2026-09-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply latest patch
AI Analysis

Impact

Authenticated users can craft requests to the ratings and favorites endpoints with arbitrary user identifiers, bypassing the ownership check. This allows the disclosure of private recipe identifiers, rating values, and favorite flags for users in other groups or households, thereby violating user privacy and potentially exposing sensitive content.

Affected Systems

The vulnerability affects all installations of Mealie from versions prior to 3.21.0. The affected product is Mealie, a recipe management application maintained by mealie-recipes. Any instance running a vulnerable version and accessible to authenticated users is impacted.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. The EPSS score of 0.0028 indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack requires only valid authentication and does not require elevated privileges, making it relatively straightforward for an attacker with access to any user account to pull data about other users.

Generated by OpenCVE AI on September 19, 2026 at 17:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Mealie 3.21.0 or newer, which includes proper ownership validation for the ratings and favorites endpoints.
  • Perform a configuration audit to ensure that only authorized roles can access the ratings API, and consider disabling it for users who do not need it.
  • Implement additional input validation to guarantee that the requested user ID matches the authenticated owner before returning any data, addressing the CWE‑639 vulnerability.

Generated by OpenCVE AI on September 19, 2026 at 17:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Mealie-recipes
Mealie-recipes mealie
Vendors & Products Mealie-recipes
Mealie-recipes mealie

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Description Mealie before 3.21.0 fails to validate user ownership in the ratings and favorites endpoints, allowing authenticated attackers to read any user's recipe ratings and favorites by specifying arbitrary user IDs in the URL path. Attackers can access private recipe identifiers, rating values, and favorite flags belonging to other users across different groups or households.
Title Mealie before 3.21.0 Information Disclosure via Ratings Endpoint
First Time appeared Mealie
Mealie mealie
Weaknesses CWE-639
CPEs cpe:2.3:a:mealie:mealie:*:*:*:*:*:*:*:*
Vendors & Products Mealie
Mealie mealie
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Mealie Mealie
Mealie-recipes Mealie
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-18T17:25:44.305Z

Reserved: 2026-09-18T15:38:23.485Z

Link: CVE-2026-93736

cve-icon Vulnrichment

Updated: 2026-09-18T17:25:26.168Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T16:17:16.170

Modified: 2026-09-22T20:53:07.383

Link: CVE-2026-93736

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T17:45:17Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key