Cross-Tenant IDOR in Shelf Tracking Platform by Shelf
CVE-2026-47697
7.1HIGH
What is CVE-2026-47697?
The Shelf Tracking Platform, utilized for managing physical assets, is vulnerable to a cross-tenant Insecure Direct Object Reference (IDOR) issue. This vulnerability allows authenticated users from one organization to access and manipulate data belonging to another organization using entity IDs. Specifically, prior to version 1.20.2, the platform failed to properly validate organization boundaries for several endpoints, leading to security risks where entities from different organizations could inadvertently interact with one another. The vulnerability has been addressed in version 1.20.2, but no workarounds are available.
Affected Version(s)
shelf.nu < 1.20.2
