CVE-2026-61744 | InvenTree up to 1.3.x Barcode Plugin /api/barcode/ InvenTreeBarcodeMixin.format_matched_response pk privileges management

SecurityVulns

A vulnerability labeled as problematic has been found in InvenTree up to 1.3.x. Affected by this issue is the function InvenTreeBarcodeMixin.format_matched_response of the file /api/barcode/ of the component Barcode Plugin. The manipulation of the argument pk results in improper privilege management.

This vulnerability is reported as CVE-2026-61744. The attack can be launched remotely. No exploit exists.

The affected component should be upgraded.VulDB Recent EntriesRead More