Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-61748— InvenTree: Report/Label print endpoints ignore per-model permissions

Quick assessment

Affected
inventree InvenTree
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

InvenTree 是一个开源库存管理系统。在 1.4.0 之前,POST /api/report/print/ 接口中的 ReportPrint 和 POST /api/report/label/print/ 接口中的 LabelPrint 虽然要求身份验证,但在通过主键选择对象并使用指定模板进行渲染之前,并未调用 来检查调用者对相应数据模型是否具有查看权限。由于主要业务模型默认存在模板,且 会为请求用户存储生成的文件,因此无权限角色或无关角色的账户可以枚举对象标识符,并下载包含采购、销售、零件、物料清单(BOM

CVSS 4.3 · Medium EPSS 0.42% · P34

Possible ATT&CK Techniques 1 AI

T1078 · Valid Accounts

Affected Version Matrix 1

VendorProduct Version RangeStatus
inventree InvenTree < 1.4.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-61748

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
InvenTree: Report/Label print endpoints ignore per-model permissions
Source: CVE Program / CVE List V5
Vulnerability Description
InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, ReportPrint at POST /api/report/print/ and LabelPrint at POST /api/report/label/print/ require authentication but do not call users.permissions.check_user_permission for the caller's per-model view role before selecting objects by primary key and rendering them with a chosen template. Because default templates exist for major business models and DataOutput stores the generated artifact for the requesting user, a role-less or unrelated-role account can enumerate object identifiers and download reports containing purchase, sales, part, bill-of-materials, stock, build, supplier, customer, pricing, and inventory data that the corresponding detail APIs would deny. This issue is fixed in version 1.4.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
通过用户控制密钥绕过授权机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
inventree InvenTree < 1.4.0 -

II. Public POCs for CVE-2026-61748

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-61748

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-61748 (2)

Other References for CVE-2026-61748 (2)

Same Patch Batch · inventree · 2026-09-21 · 6 CVEs total

CVE-2026-61749 6.5 MEDIUM InvenTree: Administrative staff users can trigger Arbitrary File Read leading to Credentia
CVE-2026-61744 6.5 MEDIUM InvenTree: Barcode-scan API (`POST /api/barcode/`) returns full serialized object data wit
CVE-2026-61746 5.3 MEDIUM InvenTree: Plugin-settings GET endpoints are readable without authentication
CVE-2026-61747 4.3 MEDIUM InvenTree: Authenticated IDOR in the data-import API exposes other users' imported rows (`
CVE-2026-61745 4.3 MEDIUM InvenTree: Missing authorization on machine restart endpoint allows any authenticated user

IV. Related Vulnerabilities

V. Comments for CVE-2026-61748

No comments yet


Leave a comment