OVERVIEW CVE-2026-35488 is an authorization bypass vulnerability in Tandoor Recipes versions prior to 2.6.4. The CustomIsShared permission class fails to properly validate HTTP methods when granting access to shared recipe books, allowing any user with read-only shared access to modify or delete recipe books through PUT, PATCH, and DELETE requests. This represents a critical data integrity and availability risk for all deployments of the affected software. SEVERITY The vulnerability carries a CVSS 3.1 score of 8.1 (HIGH) due to its network-accessible attack surface, low complexity, and requirement for only basic user-level privileges to exploit. The primary impact is integrity and availability compromise, as authenticated users can permanently delete or overwrite shared recipe books without proper authorization. The attack requires no user interaction and can be executed remotely by any authenticated user with sharing permissions. EXPLOITATION STATUS This vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and shows no indication of active exploitation in the wild. The extremely low EPSS score of 0.00016 and inactive status on security hot lists suggest minimal community attention and exploit availability. Organizations should still prioritize patching to version 2.6.4 or later to mitigate the authorization control defect before potential exploitation techniques emerge.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.6.4CPE matchmatch criteria | cpe:2.3:a:tandoor:recipes:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.