Junglewise Threat Intelligence

CVE-2026-61744: InvenTree information disclosure via barcode API

CVE-2026-61744 · Severity: medium · CVSS 6.5 · Published 2026-09-21

Technologies: InvenTree. Vendors: InvenTree.

Executive brief

InvenTree is an open-source inventory management system used to track parts, stock, and orders. A flaw in the barcode scanning API allows low-privilege users to access sensitive business data including pricing, supplier information, and customer orders by submitting specially crafted requests. This could expose commercially sensitive inventory details to competitors or malicious insiders.

Technical details

The POST /api/barcode/ endpoint uses insufficient permission checks (IsAuthenticatedOrReadScope) and the barcode plugin's format_matched_response() method returns complete model serializer output without validating the caller's per-model view permissions. An authenticated attacker can enumerate primary keys across multiple object types (parts, stock, locations, suppliers, manufacturers, orders, builds) to retrieve sensitive data. The vulnerability was patched in version 1.4.0 by adding per-model permission validation to barcode scan operations.

Affected products

  • InvenTree InvenTree before 1.4.0

Timeline

  • 2026-09-21: disclosed
  • 2026-06-24: patched: Fix merged in commit f21bc2d, released in version 1.4.0

References

Related threats