InvenTree is an Open Source Inventory Management System. From 0.16.0 to before 1.2.7, any authenticated InvenTree user can create a valid API token attributed to any other user in the system — including administrators and superusers — by supplying the target's user ID in the user field of a POST /api/user/tokens/ request. The returned token is immediately usable for full API authentication as the target user, from any network location, with no further interaction required. This vulnerability is fixed in 1.2.7 and 1.3.0.
References
| Link | Resource |
|---|---|
| https://github.com/inventree/InvenTree/security/advisories/GHSA-qh5j-c28q-c4rg | Third Party Advisory |
Configurations
History
20 Apr 2026, 15:12
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Inventree Project
Inventree Project inventree |
|
| CPE | cpe:2.3:a:inventree_project:inventree:*:*:*:*:*:*:*:* | |
| References | () https://github.com/inventree/InvenTree/security/advisories/GHSA-qh5j-c28q-c4rg - Third Party Advisory |
08 Apr 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-08 20:16
Updated : 2026-04-20 15:12
NVD link : CVE-2026-35478
Mitre link : CVE-2026-35478
CVE.ORG link : CVE-2026-35478
JSON object : View
Products Affected
inventree_project
- inventree
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
