Sploitus

CVE-2026-35478

No indexed exploits for CVE-2026-35478 yet

InvenTree is an Open Source Inventory Management System. From 0.16.0 to before 1.2.7, any authenticated InvenTree user can create a valid API token attributed to any other user in the system β€” including administrators and superusers β€” by supplying the target's user ID in the user field of a POST /api/user/tokens/ request. The returned token is immediately usable for full API authentication as the target user, from any network location, with no further interaction required. This vulnerability is fixed in 1.2.7 and 1.3.0.

Affected products
Inventree
Inventree Project Inventree
≀ 1.2.6
Fix
Available
CVSS 3.1
8.3 HIGH
EPSS
0.3% (23th percentile)
Weakness
CWE-639
NVD status
Analyzed
Published
2026-04-08
CVE-2026-35478 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-35478 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-35478 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows β€” not that no exploit exists.