CVE-2026-35476High· 7.2▾ TwilightInvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, a non-staff authenticated user can elevate their account to a staff level via a POST request against their user account endpoint. The write permissions on…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, a non-staff authenticated user can elevate their account to a staff level via a POST request against their user account endpoint. The write permissions on the API endpoint are improperly configured, allowing any user to change their staff status. This vulnerability is fixed in 1.2.7 and 1.3.0.
inventree <= 1.2.6Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-35479Medium· 6.6InvenTree is an Open Source Inventory Management System
CVE-2026-39362High· 7.1InvenTree is an Open Source Inventory Management System
CVE-2026-35477Medium· 5.5InvenTree is an Open Source Inventory Management System
CVE-2026-35478High· 8.3InvenTree is an Open Source Inventory Management System
CVE-2026-61748Medium· 4.3InvenTree is an Open Source Inventory Management System
CVE-2026-61746Medium· 5.3InvenTree is an Open Source Inventory Management System