PT-2026-62113 · Shelf · Shelf

CVE-2026-47697

·

Published

2026-07-21

·

Updated

2026-07-21

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Shelf versions prior to 1.20.2
Description Shelf is a multi-tenant platform for tracking physical assets where data is isolated by organization. Several endpoints failed to verify if entity IDs provided in request inputs belonged to the caller's organization before performing read, update, or connect operations. This allows an authenticated user from one organization to access or modify data belonging to another organization if they possess the target entity ID, resulting in a cross-tenant Insecure Direct Object Reference (IDOR), which is a flaw where an application provides direct access to objects based on user-supplied input. Additionally, a restriction on personal-workspace bookings for loader-only users could be bypassed using a crafted POST request.
Recommendations Update to version 1.20.2.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47697
GHSA-R46P-GFRP-XXGQ

Affected Products

Shelf