HIGH🇵🇱 Wersja polska

CVE-2026-35476

CVSS 7.2v3.1pub. 2026-04-08upd. 2026-07-24

InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, a non-staff authenticated user can elevate their account to a staff level via a POST request against their user account endpoint. The write permissions on the API endpoint are improperly configured, allowing any user to change their staff status. This vulnerability is fixed in 1.2.7 and 1.3.0.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
  • Inventree Project Inventree

    APP
    Inventree Project
    ≤ 1.2.6
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-35478HIGH8.3same product

InvenTree is an Open Source Inventory Management System. From 0.16.0 to before 1.2.7, any authenticated InvenT...

CVE-2026-33530HIGH7.7same product

InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, certain API endpoints associa...

CVE-2024-47610HIGH7.3same product

InvenTree is an Open Source Inventory Management System. In affected versions of InvenTree it is possible for ...

CVE-2022-2111HIGH8.8same product

Unrestricted Upload of File with Dangerous Type in GitHub repository inventree/inventree prior to 0.7.2.

CVE-2022-2112HIGH8.8same product

Improper Neutralization of Formula Elements in a CSV File in GitHub repository inventree/inventree prior to 0....