CVE-2026-33152Disclosure(tandoor / recipes)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (4 latest mentions)

Immediate actions

  • Patch tandoor recipes systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, Tandoor Recipes configures Django REST Framework with BasicAuthentication as one of the default authentication backends. The AllAuth rate limiting configuration (ACCOUNT_RATE_LIMITS: login: 5/m/ip) only applies to the HTML-based login endpoint at /accounts/login/. Any API endpoint that accepts authenticated requests can be targeted via Authorization: Basic headers with zero rate limiting, zero account lockout, and unlimited attempts. An attacker can perform high-speed password guessing against any known username. Version 2.6.0 patches the issue.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-307

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • recipes

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
recipes

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-26: 4PoC Mentioned / Linked · 2026-03-26: 1Patch / Workaround · 2026-03-26: 1Technical Details · 2026-03-26: 303-26
Signal classification3 categories
Disclosure
250.0%
Patch
125.0%
PoC
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-33152 Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, Tandoor Recipes configures Django RES… https://www.cve.org/CVERecord?id=CVE-2026-33152

    Post summary

    A brief disclosure of CVE-2026-33152 focusing on affected versions and Django configuration, without details on exploitation or remediation.

    00000147
    56.9K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-33152 - Critical Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, Tandoor Recipes configures Django REST Framework with Basi... https://www.thehackerwire.com/vulnerability/CVE-2026-33152/ https://t.co/74AT1hMtaa

    Post summary

    The post announces a critical vulnerability (CVE-2026-33152) affecting Tandoor Recipes prior to version 2.6.0, but provides no PoC, exploit code, active exploitation evidence, patch information, or detailed technical specifics.

    0000024
    163 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-33152: CRITICAL] Prior to version 2.6.0, Tandoor Recipes had a severe security flaw where BasicAuthentication lacked rate limiting in API endpoints, exposing it to brute force attacks. Update to 2....#cve,CVE-2026-33152,#cybersecurity https://cvefind.com/CVE-2026-33152

    Post summary

    The post highlights a CVE affecting Tandoor Recipes that lacks rate limiting in BasicAuthentication, but it indicates that upgrading to version 2.6.0 or later resolves the issue.

    0000031
    617 followersView on X
  • 0day Signal@0dayPublishing
    PoC

    🚨 CVE-2026-33152: Tandoor Recipes Vulnerable to Un... Basic auth bypass on recipe app = unlimited password spraying against any API endpoint while HTML login gets rate limit... https://zerodaysignal.com/vulnerability/CVE-2026-33152 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A Proof of Concept for CVE-2026-33152 is shared via an external link, indicating an authentication bypass that allows unlimited password spraying, though no active exploitation or patch information is provided.

    0000054
    194 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptandoorrecipes---

Explore more