CVE-2026-35476 Details
Description
InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, a non-staff authenticated user can elevate their account to a staff level via a POST request against their user account endpoint. The write permissions on the API endpoint are improperly configured, allowing any user to change their staff status. This vulnerability is fixed in 1.2.7 and 1.3.0.
A privilege escalation vulnerability has been identified in InvenTree, an open-source inventory management system, affecting versions prior to 1.2.7 and 1.3.0. The vulnerability allows non-staff authenticated users to elevate their account to staff level by sending a POST request to their user account endpoint. This issue arises from improper configuration of write permissions on the API endpoint, enabling any user to modify their staff status. The vulnerability requires valid user authentication to exploit, but the attack complexity is low.
Users can upgrade to InvenTree versions 1.2.7 or 1.3.0 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://docs.inventree.org/en/stable/concepts/threat_model/#assumed-trust | [email protected] | Product |
| https://github.com/inventree/InvenTree/security/advisories/GHSA-r8q5-3595-3jh2 | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-285 | Improper Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| inventree project inventree | <= 1.2.6 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 21, 2026 | Initial Analysis | [email protected] |
| Apr 8, 2026 | New CVE Received | [email protected] |