Cross-Tenant IDOR in Shelf Tracking Platform by Shelf
CVE-2026-47697

7.1HIGH

Key Information:

Vendor

Shelf-nu

Status
Vendor
CVE Published:
21 July 2026

What is CVE-2026-47697?

The Shelf Tracking Platform, utilized for managing physical assets, is vulnerable to a cross-tenant Insecure Direct Object Reference (IDOR) issue. This vulnerability allows authenticated users from one organization to access and manipulate data belonging to another organization using entity IDs. Specifically, prior to version 1.20.2, the platform failed to properly validate organization boundaries for several endpoints, leading to security risks where entities from different organizations could inadvertently interact with one another. The vulnerability has been addressed in version 1.20.2, but no workarounds are available.

Affected Version(s)

shelf.nu < 1.20.2

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.