---
id: CVE-2026-35478
title: InvenTree is an Open Source Inventory Management System
summary: >-
  InvenTree is an Open Source Inventory Management System. From 0.16.0 to before
  1.2.7, any authenticated InvenTree user can create a valid API token
  attributed to any other user in the system — including administrators and
  superusers — by…
severity: high
cvss: 8.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L'
cwe:
  - CWE-639
vendor: inventree_project
product: inventree
affected:
  - 'inventree >= 0.16.0, <= 1.2.6'
published: '2026-04-08'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T22:10:00.247'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-35478'
references:
  - url: >-
      https://github.com/inventree/InvenTree/security/advisories/GHSA-qh5j-c28q-c4rg
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00435
epssPercentile: 0.35708
ingestedAt: '2026-10-06T22:23:15.919Z'
---

## Overview

InvenTree is an Open Source Inventory Management System. From 0.16.0 to before 1.2.7, any authenticated InvenTree user can create a valid API token attributed to any other user in the system — including administrators and superusers — by supplying the target's user ID in the user field of a POST /api/user/tokens/ request. The returned token is immediately usable for full API authentication as the target user, from any network location, with no further interaction required. This vulnerability is fixed in 1.2.7 and 1.3.0.

## Affected

- `inventree >= 0.16.0, <= 1.2.6`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
