Security Flaw in InvenTree Inventory Management System
CVE-2026-61748

4.3MEDIUM

Key Information:

Vendor

Inventree

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-61748?

In the InvenTree inventory management system, prior to version 1.4.0, the ReportPrint and LabelPrint endpoints require authentication without properly validating user permissions. This oversight allows users without appropriate roles to access and enumerate sensitive data identifiers. Consequently, they can download reports containing confidential business information such as purchase and sales data, supplier details, and inventory records, which should be restricted under the relevant detail APIs. The vulnerability has been addressed in version 1.4.0.

Affected Version(s)

InvenTree < 1.4.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.