MEDIUM
TomBursch
CVE published 2026-09-27
CVE-2026-101033
Authenticated attackers can enumerate category IDs from other households to read their category names, budgets, and colors in KitchenOwl through 0.7.10, breaking household isolation. This issue arises from the lack of verification for category IDs belonging to the caller's household in expense and item operations. Defenders should assess exposure and verify household isolation to prevent unauthorized acce [truncated]