Open Food Network patches high-severity bug letting shops alter rival stores' customer balances

A high-severity broken object-level authorization vulnerability was discovered in Open Food Network (OFN), the platform used by food hubs and farmer co-ops worldwide. The flaw in the POST /api/v1/customer_account_transaction endpoint allowed any enterprise manager to create, modify, or read financial ledger entries belonging to customers of other enterprises by supplying an arbitrary customer ID in the request body. The bug, classified as CWE-639 and CWE-862 with a CVSS score of 7.1, became exploitable across all instances after version 5.7.1 removed a feature flag that had previously restricted access to the vulnerable API. OFN's authorization framework correctly scoped the parent Customer model per enterprise but failed to apply the same record-level restriction to child transaction records. The vulnerability was fixed in OFN version 5.7.4, with an advisory published on 28 July 2026 under GHSA-7cqp-qvh5-7x85; a CVE assignment is still pending.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in