Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-61744— InvenTree: Barcode-scan API (`POST /api/barcode/`) returns full serialized object data without enforcing the model's view role

Quick assessment

Affected
inventree InvenTree
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

InvenTree 是一个开源的库存管理系统。在 1.4.0 版本之前, 接口允许攻击者构造并发送包含小写模型标签(model label)和整数主键(primary key)的内部 JSON 条码数据。同时, 视图仅使用 进行权限校验,意味着只需经过身份验证或拥有通用的读取权限即可访问。 系统内置的条码插件通过 直接获取对应对象,而 方法在未检查调用者对具体模型的视图权限(view role)的情况下,直接返回该模型的完整序列化数据作为实例输出。 因此,一个低权限用户可以枚举部件(parts)、库存(stock)

CVSS 6.5 · Medium EPSS 0.51% · P41

Possible ATT&CK Techniques 1 AI

T1592 · Gather Victim Host Information

Affected Version Matrix 1

VendorProduct Version RangeStatus
inventree InvenTree < 1.4.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-61744

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
InvenTree: Barcode-scan API (`POST /api/barcode/`) returns full serialized object data without enforcing the model's view role
Source: CVE Program / CVE List V5
Vulnerability Description
InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, POST /api/barcode/ accepts an attacker-synthesized internal JSON barcode containing a lowercase model label and integer primary key, while BarcodeView uses IsAuthenticatedOrReadScope and requires only authentication or a general read scope. The built-in barcode plugin selects the object with model.objects.get(pk=...), and InvenTreeBarcodeMixin.format_matched_response() returns the complete model serializer output as instance without checking the caller's per-model view role. A low-privilege user can enumerate primary keys for parts, stock, locations, supplier and manufacturer parts, orders, and builds to disclose commercially sensitive inventory, pricing, supplier, customer, and order data. This issue is fixed in version 1.4.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
通过用户控制密钥绕过授权机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
inventree InvenTree < 1.4.0 -

II. Public POCs for CVE-2026-61744

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-61744

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-61744 (2)

Other References for CVE-2026-61744 (2)

Same Patch Batch · inventree · 2026-09-21 · 6 CVEs total

CVE-2026-61749 6.5 MEDIUM InvenTree: Administrative staff users can trigger Arbitrary File Read leading to Credentia
CVE-2026-61746 5.3 MEDIUM InvenTree: Plugin-settings GET endpoints are readable without authentication
CVE-2026-61748 4.3 MEDIUM InvenTree: Report/Label print endpoints ignore per-model permissions
CVE-2026-61747 4.3 MEDIUM InvenTree: Authenticated IDOR in the data-import API exposes other users' imported rows (`
CVE-2026-61745 4.3 MEDIUM InvenTree: Missing authorization on machine restart endpoint allows any authenticated user

IV. Related Vulnerabilities

V. Comments for CVE-2026-61744

No comments yet


Leave a comment