CVE-2026-61744 | InvenTree up to 1.3.x Barcode Plugin /api/barcode/ InvenTreeBarcodeMixin.format_matched_response pk privileges management
A vulnerability labeled as problematic has been found in InvenTree up to 1.3.x. Affected by this issue is the function InvenTreeBarcodeMixin.format_matched_response of the file /api/barcode/ of the component Barcode Plugin. The manipulation of the argument pk results in improper privilege management.
This vulnerability is reported as CVE-2026-61744. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.VulDB Recent EntriesRead More