PT-2026-31436 · Inventree · Inventree
Published
2026-04-08
·
Updated
2026-04-08
·
CVE-2026-35479
CVSS v3.1
6.6
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
InvenTree versions prior to 1.2.7 and 1.3.0
Description
InvenTree versions before 1.2.7 and 1.3.0 allow staff users with staff access permissions to install plugins via the API without superuser access. This bypasses the usual security measures requiring superuser privileges for plugin installation, potentially enabling the installation of harmful plugins. The API endpoint used for plugin installation does not properly enforce the necessary permission checks.
Recommendations
Update to InvenTree version 1.2.7 or 1.3.0.
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Inventree