Security Flaw in InvenTree Inventory Management System
CVE-2026-61748
4.3MEDIUM
What is CVE-2026-61748?
In the InvenTree inventory management system, prior to version 1.4.0, the ReportPrint and LabelPrint endpoints require authentication without properly validating user permissions. This oversight allows users without appropriate roles to access and enumerate sensitive data identifiers. Consequently, they can download reports containing confidential business information such as purchase and sales data, supplier details, and inventory records, which should be restricted under the relevant detail APIs. The vulnerability has been addressed in version 1.4.0.
Affected Version(s)
InvenTree < 1.4.0
