CVE-2026-35489 | TandoorRecipes recipes up to 2.6.3 /api/food/{id}/shopping/ ShoppingListEntry.objects.create Amount authorization
A vulnerability classified as critical was found in TandoorRecipes recipes up to 2.6.3. Affected by this issue is the function ShoppingListEntry.objects.create of the file /api/food/{id}/shopping/. Such manipulation of the argument Amount leads to authorization bypass.
This vulnerability is documented as CVE-2026-35489. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.