Report: CVE-2026-35479 - InvenTree Plugin Installation - Insufficient Permissions

Report: CVE-2026-35479 - InvenTree Plugin Installation - Insufficient Permissions

CVE ID :CVE-2026-35479 Published : April 8, 2026, 8:16 p.m. | 18 minutes ago Description :InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, any users who have staff access permissions can install plugins via the API, without requiring

CVE Details

Published
April 8, 2026