Sploitus

CVE-2026-35476

No indexed exploits for CVE-2026-35476 yet

InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, a non-staff authenticated user can elevate their account to a staff level via a POST request against their user account endpoint. The write permissions on the API endpoint are improperly configured, allowing any user to change their staff status. This vulnerability is fixed in 1.2.7 and 1.3.0.

Affected products
Inventree
Inventree Project Inventree
≤ 1.2.6
Fix
Available
CVSS 3.1
7.2 HIGH
EPSS
0.1% (4th percentile)
Weakness
CWE-285
NVD status
Analyzed
Published
2026-04-08
CVE-2026-35476 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-35476 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-35476 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.