Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-61746— InvenTree: Plugin-settings GET endpoints are readable without authentication

Quick assessment

Affected
inventree InvenTree
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

InvenTree 是一个开源的库存管理系统。在 1.4.0 版本之前,PluginSettingList、PluginAllSettingList 和 PluginSettingDetail 在设置 GlobalSettingsPermissions 时,未包含项目默认的全局设置端点所使用的 IsAuthenticated 权限。由于 GlobalSettingsPermissions 对安全方法(如 GET 请求)返回 true,而 AuthRequiredMiddleware 又排除了以 /api/ 开头的路

CVSS 5.3 · Medium EPSS 0.40% · P32

Possible ATT&CK Techniques 1 AI

T1592 · Gather Victim Host Information

Affected Version Matrix 1

VendorProduct Version RangeStatus
inventree InvenTree < 1.4.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-61746

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
InvenTree: Plugin-settings GET endpoints are readable without authentication
Source: CVE Program / CVE List V5
Vulnerability Description
InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, PluginSettingList, PluginAllSettingList, and PluginSettingDetail set GlobalSettingsPermissions without the IsAuthenticated permission used by the project default and equivalent global-settings endpoints. GlobalSettingsPermissions returns true for safe methods, while AuthRequiredMiddleware exempts /api/ paths, so an unauthenticated caller can retrieve plugin names, setting keys, descriptions, types, choices, and non-protected configuration values through /api/plugin/settings/ and the per-plugin settings endpoints. Protected secret values remain masked as three asterisks, limiting the issue to metadata and non-secret configuration disclosure. This issue is fixed in version 1.4.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
inventree InvenTree < 1.4.0 -

II. Public POCs for CVE-2026-61746

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-61746

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-61746 (2)

Other References for CVE-2026-61746 (2)

Same Patch Batch · inventree · 2026-09-21 · 6 CVEs total

CVE-2026-61749 6.5 MEDIUM InvenTree: Administrative staff users can trigger Arbitrary File Read leading to Credentia
CVE-2026-61744 6.5 MEDIUM InvenTree: Barcode-scan API (`POST /api/barcode/`) returns full serialized object data wit
CVE-2026-61748 4.3 MEDIUM InvenTree: Report/Label print endpoints ignore per-model permissions
CVE-2026-61747 4.3 MEDIUM InvenTree: Authenticated IDOR in the data-import API exposes other users' imported rows (`
CVE-2026-61745 4.3 MEDIUM InvenTree: Missing authorization on machine restart endpoint allows any authenticated user

IV. Related Vulnerabilities

V. Comments for CVE-2026-61746

No comments yet


Leave a comment