CVE-2026-35476 HIGH

CVE-2026-35476: InvenTree Affected by Privilege Escalation via API

Vendor Inventree
Product InvenTree
Weakness CWE-285
Published April 8, 2026
Last update April 8, 2026

CVSS base score

7.2/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

What the vulnerability does

01Description

InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, a non-staff authenticated user can elevate their account to a staff level via a POST request against their user account endpoint. The write permissions on the API endpoint are improperly configured, allowing any user to change their staff status. This vulnerability is fixed in 1.2.7 and 1.3.0.

Key dates

02Disclosure timeline

April 8, 2026 CVE published
April 8, 2026 Record updated