CVE-2026-35479: InvenTree Plugin Installation - Insufficient Permissions
InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, any users who have staff access permissions can install plugins via the API, without requiring "superuser" account access. This level of permission requirement is out of alignment with other plugin actions (such as uninstalling) which do require superuser access. The vulnerability allows staff users (who may be considered to have a lower level of trust than a superuser account) to install arbitrary (and potentially harmful) plugins. This vulnerability is fixed in 1.2.7 and 1.3.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
InvenTreeto a version that resolves this vulnerability.Fixed in 1.2.7 - Upgrade
Upgrade
InvenTreeto a version that resolves this vulnerability.Fixed in 1.3.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35479?
CVE-2026-35479 is classified as a moderate severity vulnerability due to insufficient permission controls.
How do I fix CVE-2026-35479?
To fix CVE-2026-35479, upgrade InvenTree to version 1.2.7 or 1.3.0 or later.
Who is affected by CVE-2026-35479?
CVE-2026-35479 affects users of InvenTree versions prior to 1.2.7 and 1.3.0 with staff access permissions.
What are the implications of CVE-2026-35479?
The implications of CVE-2026-35479 include allowing unauthorized users to install plugins through the API.
Is there a workaround for CVE-2026-35479?
A temporary workaround for CVE-2026-35479 is to restrict staff access permissions until the software is updated.