


Perceptive Security
SOC/SIEM Consultancy

InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, a non-staff authenticated user can elevate their account to a staff level via…
Published:
7 april 2026 om 22:00:00
Alert date:
8 april 2026 om 21:02:10
Source:
nvd.nist.gov
Enterprise Applications, Identity & Access
InvenTree Open Source Inventory Management System contains a privilege escalation vulnerability in versions prior to 1.2.7 and 1.3.0. A non-staff authenticated user can elevate their account to staff level via a POST request to their user account endpoint. The vulnerability stems from improperly configured write permissions on the API endpoint, allowing any user to modify their staff status. This represents a critical access control bypass that could lead to unauthorized administrative access. The issue has been patched in versions 1.2.7 and 1.3.0.
Technical details
Mitigation steps:
Affected products:
InvenTree
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-35476
https://docs.inventree.org/en/stable/concepts/threat_model/#assumed-trust
https://github.com/inventree/InvenTree/security/advisories/GHSA-r8q5-3595-3jh2
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
