Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-35488

27
FAUCET Score

OVERVIEW CVE-2026-35488 is an authorization bypass vulnerability in Tandoor Recipes versions prior to 2.6.4. The CustomIsShared permission class fails to properly validate HTTP methods when granting access to shared recipe books, allowing any user with read-only shared access to modify or delete recipe books through PUT, PATCH, and DELETE requests. This represents a critical data integrity and availability risk for all deployments of the affected software. SEVERITY The vulnerability carries a CVSS 3.1 score of 8.1 (HIGH) due to its network-accessible attack surface, low complexity, and requirement for only basic user-level privileges to exploit. The primary impact is integrity and availability compromise, as authenticated users can permanently delete or overwrite shared recipe books without proper authorization. The attack requires no user interaction and can be executed remotely by any authenticated user with sharing permissions. EXPLOITATION STATUS This vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and shows no indication of active exploitation in the wild. The extremely low EPSS score of 0.00016 and inactive status on security hot lists suggest minimal community attention and exploit availability. Organizations should still prioritize patching to version 2.6.4 or later to mitigate the authorization control defect before potential exploitation techniques emerge.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.6.4CPE matchmatch criteria
cpe:2.3:a:tandoor:recipes:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.1HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.38%
Probability of exploitation in next 30 days
EPSS Percentile
30.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0038 is in the 18th percentile among its peer group of 17,829 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / TandoorRecipes/recipes/releases/tag/2.6.4
ProductRelease Notes
github.com / TandoorRecipes/recipes/security/advisories/GHSA-xvmf-cfrq-4j8f
ExploitMitigationVendor Advisory