CVE-2026-35479Disclosure(inventree_project / inventree)

LOWCVSS 4.7 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, any users who have staff access permissions can install plugins via the API, without requiring "superuser" account access. This level of permission requirement is out of alignment with other plugin actions (such as uninstalling) which do require superuser access. The vulnerability allows staff users (who may be considered to have a lower level of trust than a superuser account) to install arbitrary (and potentially harmful) plugins. This vulnerability is fixed in 1.2.7 and 1.3.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-285

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • inventree

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
inventree

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-08: 1Technical Details · 2026-04-08: 104-08
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-35479 Unauthorized Plugin Installation via API in InvenTree Below 1.2.7 and 1.3.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-35479

    Post summary

    The text is a straightforward disclosure of CVE‑2026‑35479, noting an unauthorized plugin installation flaw in InvenTree versions below 1.2.7 and 1.3.0, with no PoC, exploit, or mitigation information provided.

    0000029
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appinventree_projectinventree---

Explore more