PatchSiren

inventree CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM inventree CVE published 2026-04-08

CVE-2026-35479

A vulnerability was discovered in InvenTree, an Open Source Inventory Management System. Staff users with specific permissions can install plugins via the API without requiring superuser account access. This issue arises from inconsistent permission requirements for plugin actions, where installing plugins does not require superuser access unlike uninstalling plugins. The vulnerability has a CVSS score of [truncated]

HIGH inventree CVE published 2026-04-08

CVE-2026-35478

CVE-2026-35478 is a high-severity vulnerability in InvenTree, an Open Source Inventory Management System. An authenticated user can create a valid API token for any other user, including administrators and superusers, by providing the target user's ID in a POST /api/user/tokens/ request. The returned token allows for full API authentication as the target user from any network location without further inte [truncated]

MEDIUM inventree CVE published 2026-04-08

CVE-2026-35477

CVE-2026-35477 is a vulnerability in InvenTree, an Open Source Inventory Management System, affecting versions from 1.2.3 to 1.2.6. The vulnerability arises from the incomplete fix for CVE-2026-27629, which upgraded the PART_NAME_FORMAT validator to use jinja2.sandbox.SandboxedEnvironment but did not update the actual renderer in part/helpers.py. This allows a staff user with settings access to craft a te [truncated]

HIGH inventree CVE published 2026-04-08

CVE-2026-35476

CVE-2026-35476 is a HIGH severity vulnerability in InvenTree Open Source Inventory Management System prior to 1.2.7 and 1.3.0. A non-staff authenticated user can elevate their account to a staff level via a POST request against their user account endpoint. The write permissions on the API endpoint are improperly configured, allowing any user to change their staff status. This vulnerability has a CVSS scor [truncated]