Executive brief
InvenTree, an open-source inventory management system, contains a security flaw that allows regular users to grant themselves administrative (staff) privileges. By sending a specially crafted request to the system's programming interface, a user can bypass intended restrictions and gain elevated control over the platform. This could allow an unauthorized individual to modify inventory records, access sensitive business data, or disrupt operations.
Technical details
A privilege escalation vulnerability exists in InvenTree due to improperly configured write permissions on the user account API endpoint. An authenticated user can submit a POST request to their own account endpoint to modify their 'is_staff' status, effectively elevating their privileges without administrative intervention. While the vendor's threat model assumes a level of trust for all users, this flaw allows a low-privileged actor to gain staff-level access. The issue is rooted in improper authorization (CWE-285) and is resolved in versions 1.2.7 and 1.3.0.
Affected products
- InvenTree InvenTree < 1.2.7, < 1.3.0
Timeline
- 2026-04-07: advisory: GitHub Security Advisory GHSA-r8q5-3595-3jh2 published
- 2026-04-08: disclosed: CVE-2026-35476 published to NVD
- 2026-04-08: patched: Fixes released in versions 1.2.7 and 1.3.0