CVE-2026-35045 affects Tandoor Recipes prior to version 2.6.4. The vulnerability is in the PUT /api/recipe/batch_update/ endpoint, which permits any authenticated user within a Space to modify arbitrary recipe objects in that same Space, including recipes marked private by other users. Unlike the standard single-recipe update endpoint (PUT /api/recipe/{id}/), the batch update functionality does not enforce the expected object-level authorization checks on each targeted recipe. As a result, an authenticated user can submit batch update requests against recipe IDs they should not be allowed to modify, leading to unauthorized changes to private recipes, shared-access settings, and recipe metadata.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a standalone Python proof-of-concept for CVE-2026-35045 / GHSA-v8x3-w674-55p5 affecting Tandoor Recipes <= 2.6.1. The exploit targets a broken object-level authorization flaw in the web API endpoint PUT /api/recipe/batch_update/, where authenticated users in the same Space can update recipes they do not own because the backend uses a DRF detail=False action that skips object-level permission checks. The main exploit file is poc.py, which logs into the application through /accounts/login/, retrieves a CSRF token and session cookie, checks whether a target recipe is inaccessible via /api/recipe/{id}/, then sends a crafted JSON PUT request to /api/recipe/batch_update/ with attacker-controlled fields such as private=false and shared_add=[attacker_user_id]. If successful, the script verifies that the previously inaccessible recipe is now readable through the normal endpoint. Capabilities include forced exposure of private recipes, unauthorized ACL manipulation, and persistence of access by adding the attacker to the shared list. The repository also includes a VulnerableTandoor lab environment with docker-compose and nginx configuration to deploy Tandoor Recipes 2.6.1 behind nginx on localhost:8085 for testing. Structure is simple: one exploit script, one top-level advisory README, and a small Docker-based vulnerable environment. This is a real exploit PoC rather than a detector, and while the payload is basic and hardcoded, it performs end-to-end exploitation and verification.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.